Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
Loading...
Loading...
This medium-severity CVE scores 6.5 under NVD CVSS v3. EPSS exploit probability: 0.3%, top 51% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
May 17, 2016
May 6, 2026
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | rubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op | 2016-08-24 | redhat |
| redhat | jenkins-plugin-openshift-pipeline-0:1.0.12-1.el7 | 2016-06-06 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.jenkins-ci.main:jenkins-core | 1.396 ... 1.651.1 (313 versions) | 1.651.2 | — |
See which npm, PyPI, Go, and Maven packages are affected by CVE-2016-3724
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.