UNKNOWN Maven

Jenkins allows for Privilege Escalation by Remote Authenticated Users

GHSA-3269-jqp5-v8c9 · CVE-2015-1814

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.

Ready to move

Start Securing

Free, no credit card | First findings in minutes