Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-5294 | Jenkins allows Administrators to Access API Tokens |
Github GHSA |
GHSA-x4m5-j4x4-4wjg | Jenkins allows Administrators to Access API Tokens |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T06:41:09.554Z
Reserved: 2015-07-01T00:00:00
Link: CVE-2015-5323
No data.
Status : Deferred
Published: 2015-11-25T20:59:14.730
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-5323
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA