Vulnerability record · CVE-2015-5317 · published 25 November 2015
CVE-2015-5317: Jenkins Fingerprints pages expose job and build names
Jenkins · Jenkins
Jenkins before 1.638 and LTS before 1.625.2 expose sensitive job and build name information through the Fingerprints pages when requested directly. The flaw is an information disclosure (CWE-200) that leaks internal build metadata to anyone who can reach the UI. It matters because that metadata aids reconnaissance and targeting of CI/CD infrastructure.
Description
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 high severity, KEV-listed with known exploitation, and high EPSS percentile, though impact is limited to information disclosure.
What it is
Jenkins before 1.638 and LTS before 1.625.2 expose sensitive job and build name information through the Fingerprints pages when requested directly. The flaw is an information disclosure (CWE-200) that leaks internal build metadata to anyone who can reach the UI. It matters because that metadata aids reconnaissance and targeting of CI/CD infrastructure.
Impact
An unauthenticated remote attacker gains sensitive job and build name information, which can reveal project structure and naming conventions useful for follow-on attacks. No integrity or availability impact is described.
Attack surface
Reachable over the network via a direct HTTP request to the Fingerprints pages; the CVSS vector shows no privileges and no user interaction required.
Exploitation
CVE-2015-5317 is listed in CISA KEV (added 2023-05-12), indicating known exploitation, and EPSS is 0.22429 (97.6th percentile). References are vendor and Red Hat advisories plus the KEV entry; no public exploit tag is present in the record.
What to do
- Upgrade Jenkins to 1.638 or later, or LTS to 1.625.2 or later, per the vendor advisory.
- Apply the referenced Red Hat errata (RHSA-2016:0070, RHSA-2016-0489) where Jenkins is packaged.
- Restrict network access to the Jenkins UI so only trusted users and networks can reach it.
- Review Jenkins job and build naming for information that should not be exposed.
- Monitor for direct requests to Fingerprints pages from untrusted sources.
Detection
- Alert on direct HTTP requests to Jenkins Fingerprints pages from unauthenticated or unexpected sources.
- Review Jenkins access logs for enumeration patterns against fingerprint and job/build endpoints.
- Audit exposed Jenkins instances for versions below 1.638 or LTS 1.625.2.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-5317 to the Known Exploited Vulnerabilities catalog on 12 May 2023 as "Jenkins User Interface (UI) Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 2 June 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://rhn.redhat.com/errata/RHSA-2016-0489.html | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2016:0070 | Third Party Advisory |
| https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11 | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2016-0489.html | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2016:0070 | Third Party Advisory |
| https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5317 | US Government Resource |
Track CVE-2015-5317 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5317), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.