UNKNOWN Maven
Jenkins allows Administrators to Access API Tokens
GHSA-x4m5-j4x4-4wjg · CVE-2015-5323
Published · Modified
Description
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2015-5323
- WEB https://github.com/jenkinsci/jenkins/commit/b3f16489ad5f15c3e749ed066cf6b4251f6668c6
- WEB https://access.redhat.com/errata/RHSA-2016:0070
- PACKAGE https://github.com/jenkinsci/jenkins
- WEB https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
- WEB http://rhn.redhat.com/errata/RHSA-2016-0489.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes