---
title: "CVE-2015-1806\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-1806?format=md
keywords: index, follow
---

# CVE-2015-1806

Publication date 16 October 2015

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The combination filter Groovy script in Jenkins before 1.600 and LTS before
1.596.1 allows remote authenticated users with job configuration permission
to gain privileges and execute arbitrary code on the master via unspecified
vectors.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| jenkins | 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.10 utopic | Not in release |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Ignored end of life |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1806)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-1806)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-1806)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-1806)

### Other references

* <https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27>
* <https://www.cve.org/CVERecord?id=CVE-2015-1806>
