CVE-2016-3721

Severity CVSS v4.0:
Pending analysis
Type:
CWE-17 Code Errors
Publication date:
17/05/2016
Last modified:
12/04/2025

Description

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:redhat:openshift:3.2:*:*:*:enterprise:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* 1.651.1 (including)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* 2.2 (including)