Описание
The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.
A flaw was found in the Jenkins API token-issuing service. The service was not properly protected against anonymous users, potentially allowing remote attackers to escalate privileges.
Дополнительная информация
Статус:
7.5 High
CVSS2
Связанные уязвимости
The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.
The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.
The API token-issuing service in Jenkins before 1.606 and LTS before 1 ...
Jenkins allows for Privilege Escalation by Remote Authenticated Users
7.5 High
CVSS2