Red Hat Bugzilla – Bug 1282367
CVE-2015-5324 jenkins: Queue API did show items not visible to the current user (SECURITY-186)
Last modified: 2016-03-23 05:13:15 EDT
The following flaw was found in Jenkins: The /queue/api URL could return information about items not accessible to the current user (such as parameter names and values, build names, project descriptions, ...). Low privileged users can gain some limited information about items they should not have access to. External References: https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
Fixed in Fedora in: jenkins-1.609.3-3.fc22 jenkins-1.625.2-2.fc23 jenkins-1.625.2-2.fc24
This issue has been addressed in the following products: RHEL 7 Version of OpenShift Enterprise 3.1 Via RHSA-2016:0070 https://access.redhat.com/errata/RHSA-2016:0070
This issue has been addressed in the following products: Red Hat OpenShift Enterprise 2.2 Via RHSA-2016:0489 https://rhn.redhat.com/errata/RHSA-2016-0489.html