Jenkins User Interface (UI) Information Disclosure Vulnerability

Added to KEV
2023-05-12
Federal due date
2023-06-02
Vendor
Jenkins
Product
Jenkins User Interface (UI)
EPSS
97.4th percentile (score 0.397, as of 2026-06-08)
NVD CVSS v3.1
Ransomware use
Unknown
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2015-5317

CISA short description

Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.

Required action

Apply updates per vendor instructions.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.