Show plain JSON{"affected_release": [{"advisory": "RHSA-2016:1206", "cpe": "cpe:/a:redhat:openshift:3.2::el7", "package": "jenkins-0:1.651.2-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.2", "release_date": "2016-06-06T00:00:00Z"}, {"advisory": "RHSA-2016:1206", "cpe": "cpe:/a:redhat:openshift:3.2::el7", "package": "jenkins-plugin-openshift-pipeline-0:1.0.12-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.2", "release_date": "2016-06-06T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "activemq-0:5.9.0-6.redhat.611463.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "ImageMagick-0:6.7.2.7-5.el6_8", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "jenkins-0:1.651.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "libcgroup-0:0.40.rc1-18.el6_8", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-broker-0:1.16.3.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-broker-util-0:1.37.6.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-cron-0:1.25.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-diy-0:1.26.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-perl-0:1.30.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-php-0:1.35.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-python-0:1.34.3.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-node-proxy-0:1.26.3.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-node-util-0:1.38.7.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rhc-0:1.38.7.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-controller-0:1.38.6.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-node-0:1.38.6.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1206", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "jenkins-0:1.651.2-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-06-06T00:00:00Z"}, {"advisory": "RHSA-2016:1206", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "jenkins-plugin-openshift-pipeline-0:1.0.12-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-06-06T00:00:00Z"}], "bugzilla": {"description": "jenkins: Regular users can trigger download of update site metadata (SECURITY-273)", "id": "1335420", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1335420"}, "csaw": false, "cvss": {"cvss_base_score": "3.5", "cvss_scoring_vector": "AV:N/AC:M/Au:S/C:N/I:N/A:P", "status": "verified"}, "details": ["Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (service disruption)."], "name": "CVE-2016-3725", "public_date": "2016-05-11T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2016-3725\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-3725\nhttps://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11"], "threat_severity": "Low"}