Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Jenkins allows Administrators to Access API Tokens

GHSA-x4m5-j4x4-4wjg · CVE-2015-5323

Published · Modified

Description

Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.

Ready to move

Start Securing

Free, no credit card | First findings in minutes