4
CVSSv2

CVE-2016-3721

Published: 17/05/2016 Updated: 02/05/2024
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Jenkins prior to 2.3 and LTS prior to 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift 3.1

redhat openshift 3.2

jenkins jenkins

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Multiple vulnerabilities in Jenkins plugins <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Daniel Beck &lt;ml () ...