CVE Vulnerabilities

CVE-2015-7539

Insufficient Verification of Data Authenticity

Published: Feb 03, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
JenkinsJenkins*1.639 (including)
Red Hat OpenShift Enterprise 2.2RedHatactivemq-0:5.9.0-6.redhat.611454.el6op*
Red Hat OpenShift Enterprise 2.2RedHatjenkins-0:1.625.3-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-enterprise-upgrade-0:2.2.9-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-broker-util-0:1.37.5.3-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-cron-0:1.25.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-haproxy-0:1.31.5.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-mysql-0:1.31.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-php-0:1.35.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-python-0:1.34.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-msg-node-mcollective-0:1.30.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-proxy-0:1.26.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-util-0:1.38.6.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatphp-0:5.3.3-46.el6_7.1*
Red Hat OpenShift Enterprise 2.2RedHatrhc-0:1.38.6.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-common-0:1.29.5.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-console-0:1.35.5.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-controller-0:1.38.5.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-frontend-apache-vhost-0:0.13.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-node-0:1.38.5.3-1.el6op*
Red Hat OpenShift Enterprise 3.1RedHatatomic-openshift-0:3.1.1.6-1.git.0.b57e8bd.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatheapster-0:0.18.2-3.gitaf4752e.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatjenkins-0:1.625.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-align-text-0:0.1.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ansi-green-0:0.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ansi-wrap-0:0.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-anymatch-0:1.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-array-unique-0:0.2.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arr-diff-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arr-flatten-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arrify-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-async-each-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-binary-extensions-0:1.3.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-braces-0:1.8.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-capture-stack-trace-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-chokidar-0:1.4.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-configstore-0:1.4.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-create-error-class-0:2.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-deep-extend-0:0.3.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-duplexer-0:0.1.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-duplexify-0:3.4.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-end-of-stream-0:1.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-error-ex-0:1.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-es6-promise-0:3.0.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-event-stream-0:3.3.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-expand-brackets-0:0.1.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-expand-range-0:1.8.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-extglob-0:0.3.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-filename-regex-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-fill-range-0:2.2.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-for-in-0:0.1.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-for-own-0:0.1.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-from-0:0.1.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-glob-base-0:0.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-glob-parent-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-got-0:5.2.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-graceful-fs-0:4.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ini-0:1.1.0-6.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-binary-path-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-dotfile-0:1.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-equal-shallow-0:0.1.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-extendable-0:0.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-extglob-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-glob-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-npm-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-number-0:2.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-isobject-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-plain-obj-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-primitive-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-redirect-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-stream-0:1.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-kind-of-0:3.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-latest-version-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lazy-cache-0:1.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.assign-0:3.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.baseassign-0:3.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.basecopy-0:3.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.bindcallback-0:3.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.createassigner-0:3.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.defaults-0:3.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.getnative-0:3.9.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isarguments-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isarray-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isiterateecall-0:3.0.9-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.keys-0:3.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.restparam-0:3.6.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lowercase-keys-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-map-stream-0:0.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-micromatch-0:2.3.5-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-mkdirp-0:0.5.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-nodemon-0:1.8.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-node-status-codes-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-normalize-path-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-object-assign-0:4.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-object.omit-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-optimist-0:0.4.0-5.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-osenv-0:0.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-os-homedir-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-os-tmpdir-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-package-json-0:2.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-parse-glob-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-parse-json-0:2.2.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pause-stream-0:0.0.11-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pinkie-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pinkie-promise-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-prepend-http-0:1.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-preserve-0:0.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ps-tree-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-randomatic-0:1.1.5-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-rc-0:1.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-read-all-stream-0:3.0.1-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-readdirp-0:2.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-regex-cache-0:0.4.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-registry-url-0:3.0.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-repeat-element-0:1.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-semver-0:5.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-semver-diff-0:2.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-slide-0:1.1.5-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-split-0:0.3.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-stream-combiner-0:0.2.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-string-length-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-strip-json-comments-0:1.0.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-success-symbol-0:0.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-through-0:2.3.4-4.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-timed-out-0:2.0.0-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-touch-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-undefsafe-0:0.0.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-unzip-response-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-update-notifier-0:0.6.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-url-parse-lax-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-uuid-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-write-file-atomic-0:1.1.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-xdg-basedir-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnss_wrapper-0:1.0.3-1.el7*
Red Hat OpenShift Enterprise 3.1RedHatopenshift-ansible-0:3.0.35-1.git.0.6a386dd.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatopenvswitch-0:2.4.0-1.el7*
Red Hat OpenShift Enterprise 3.1RedHatorigin-kibana-0:0.5.0-1.el7aos*
JenkinsUbuntuprecise*
JenkinsUbuntuupstream*

References