Описание
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.532.1 (включая)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Конфигурация 2Версия до 1.550 (включая)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.01748
Низкий
6.5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
ubuntu
почти 12 лет назад
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
redhat
больше 12 лет назад
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
debian
почти 12 лет назад
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the AP ...
github
около 4 лет назад
Jenkins does not invalidate the API token when a user is deleted
EPSS
Процентиль: 76%
0.01748
Низкий
6.5 Medium
CVSS2
Дефекты
CWE-287