CVE Vulnerabilities

CVE-2016-3721

Published: May 17, 2016 | Modified: Apr 12, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

Affected Software

NameVendorStart VersionEnd Version
OpenshiftRedhat3.1 (including)3.1 (including)
OpenshiftRedhat3.2 (including)3.2 (including)
Red Hat OpenShift Container Platform 3.2RedHatjenkins-0:1.651.2-1.el7*
Red Hat OpenShift Container Platform 3.2RedHatjenkins-plugin-openshift-pipeline-0:1.0.12-1.el7*
Red Hat OpenShift Enterprise 2.2RedHatactivemq-0:5.9.0-6.redhat.611463.el6op*
Red Hat OpenShift Enterprise 2.2RedHatImageMagick-0:6.7.2.7-5.el6_8*
Red Hat OpenShift Enterprise 2.2RedHatjenkins-0:1.651.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatlibcgroup-0:0.40.rc1-18.el6_8*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-broker-0:1.16.3.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-broker-util-0:1.37.6.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-cron-0:1.25.4.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-diy-0:1.26.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-perl-0:1.30.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-php-0:1.35.4.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-python-0:1.34.3.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-proxy-0:1.26.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-util-0:1.38.7.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrhc-0:1.38.7.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-controller-0:1.38.6.4-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-node-0:1.38.6.4-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op*
Red Hat OpenShift Enterprise 3.1RedHatjenkins-0:1.651.2-1.el7*
Red Hat OpenShift Enterprise 3.1RedHatjenkins-plugin-openshift-pipeline-0:1.0.12-1.el7*
JenkinsUbuntuprecise*

References