Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-0158

17
FAUCET Score

CVE-2013-0158 describes an unspecified vulnerability in Jenkins versions prior to 1.498, Jenkins LTS before 1.480.2, and specific Jenkins Enterprise versions. When a slave is attached and anonymous read access is enabled, remote attackers can obtain the master cryptographic key through unknown vectors. This vulnerability has a low CVSS score of 2.6, indicating a network attack vector with high attack complexity and a partial impact on confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.480.3.1CPE matchmatch criteria
cpe:2.3:a:cloudbees:jenkins:*:*:*:*:*:*:*:*
1.400CPE matchmatch criteria
cpe:2.3:a:jenkins:jenkins:1.400:*:*:*:*:*:*:*
1.401CPE matchmatch criteria
cpe:2.3:a:jenkins:jenkins:1.401:*:*:*:*:*:*:*
1.402CPE matchmatch criteria
cpe:2.3:a:jenkins:jenkins:1.402:*:*:*:*:*:*:*
1.403CPE matchmatch criteria
cpe:2.3:a:jenkins:jenkins:1.403:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.6LOW

AV:N/AC:H/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.46%
Probability of exploitation in next 30 days
EPSS Percentile
82.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0245 is in the 80th percentile among its peer group of 1,505 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

mavenpatch availablevia ghsa
Product: org.jenkins-ci.main:jenkins-coreFixed in: 1.498
mavenpatch availablevia ghsa
Product: org.jenkins-ci.main:jenkins-coreFixed in: 1.480.2
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: jenkins-0:1.498-1.1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: mongodb-0:2.0.2-6.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-console-0:0.0.13-2.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-origin-broker-0:1.0.10-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-origin-broker-util-0:1.0.14-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-origin-cartridge-haproxy-1.4-0:1.0.3-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-origin-cartridge-ruby-1.8-0:1.0.5-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-origin-cartridge-ruby-1.9-scl-0:1.0.5-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-origin-msg-node-mcollective-0:1.0.2-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-origin-node-util-0:1.0.7-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: openshift-origin-port-proxy-0:1.0.3-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rhc-0:1.3.2-1.3.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: ruby193-rubygem-activerecord-1:3.2.8-2.el6
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: ruby193-rubygem-passenger-0:3.0.12-21.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rubygem-activerecord-1:3.0.13-3.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rubygem-openshift-origin-auth-remote-user-0:1.0.4-2.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rubygem-openshift-origin-common-0:1.0.2-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rubygem-openshift-origin-console-0:1.0.6-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rubygem-openshift-origin-controller-0:1.0.11-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rubygem-openshift-origin-dns-bind-0:1.0.2-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rubygem-openshift-origin-msg-broker-mcollective-0:1.0.4-1.el6op
View patch
redhatpatch availablevia redhat_api
Product: RHEL 6 Version of OpenShift EnterpriseFixed in: rubygem-openshift-origin-node-0:1.0.10-6.el6op
View patch

Vendor Advisories (2)

mavenGHSA-jwfr-h6jp-9p2glow

Jenkins allows attackers to obtain the master cryptographic key

May 5, 2022
redhatCVE-2013-0158Important

jenkins: remote unauthenticated retrieval of master cryptographic key (Jenkins Security Advisory 2013-01-04)

Jan 4, 2013

References

rhn.redhat.com / errata/RHSA-2013-0220.html
bugzilla.redhat.com / show_bug.cgi
github.com / jenkinsci/jenkins/commit/3dc13b957b14cec649036e8dd517f0f9cb21fb04
github.com / jenkinsci/jenkins/commit/4895eaafca468b7f0f1a3166b2fca7414f0d5da5
github.com / jenkinsci/jenkins/commit/94a8789b699132dd706021a6be1b78bc47f19602
github.com / jenkinsci/jenkins/commit/a9aff088f327278a8873aef47fa8f80d3c5932fd
github.com / jenkinsci/jenkins/commit/c3d8e05a1b3d58b6c4dcff97394cb3a79608b4b2
wiki.jenkins-ci.org / display/SECURITY/Jenkins+Security+Advisory+2013-01-04
Vendor Advisory
cloudbees.com / jenkins-advisory/jenkins-security-advisory-2013-01-04.cb
Vendor Advisory
openwall.com / lists/oss-security/2013/01/07/4