Description
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-4741 | Jenkins allows Remote Users to Inject Build Parameters |
Github GHSA |
GHSA-qf2h-h3xq-j93j | Jenkins allows Remote Users to Inject Build Parameters |
References
History
Fri, 20 Feb 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T00:03:34.424Z
Reserved: 2016-03-30T00:00:00.000Z
Link: CVE-2016-3721
Updated: 2024-08-06T00:03:34.424Z
Status : Modified
Published: 2016-05-17T14:08:05.593
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-3721
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA