Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1814

Опубликовано: 23 мар. 2015
Источник: redhat
CVSS2: 7.5

Описание

The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.

A flaw was found in the Jenkins API token-issuing service. The service was not properly protected against anonymous users, potentially allowing remote attackers to escalate privileges.

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1205616jenkins: forced API token change (SECURITY-180)

7.5 High

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.

nvd
почти 11 лет назад

The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.

debian
почти 11 лет назад

The API token-issuing service in Jenkins before 1.606 and LTS before 1 ...

github
около 4 лет назад

Jenkins allows for Privilege Escalation by Remote Authenticated Users

7.5 High

CVSS2