Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-2062

Опубликовано: 17 окт. 2014
Источник: debian
EPSS Низкий

Описание

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jenkinsfixed1.565.2-1package

Примечания

  • https://github.com/jenkinsci/jenkins/commit/5548b5220cfd496831b5721124189ff18fbb12a3

EPSS

Процентиль: 75%
0.01748
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.

redhat
больше 12 лет назад

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.

nvd
почти 12 лет назад

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.

github
около 4 лет назад

Jenkins does not invalidate the API token when a user is deleted

EPSS

Процентиль: 75%
0.01748
Низкий