← Back

CVE-2016-0789

nvd nist
Published: Apr 7, 2016Modified: May 6, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Affected (3)

1 product
Jenkins
1 product
Openshift
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.642.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.649

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.