Description
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-5294 | Jenkins allows Administrators to Access API Tokens |
Github GHSA |
GHSA-x4m5-j4x4-4wjg | Jenkins allows Administrators to Access API Tokens |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T06:41:09.554Z
Reserved: 2015-07-01T00:00:00.000Z
Link: CVE-2015-5323
No data.
Status : Modified
Published: 2015-11-25T20:59:14.730
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-5323
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA