← Back

CVE-2015-5323

nvd nist
Published: Nov 25, 2015Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.

Affected (4)

1 product
Openshift
1 product
Jenkins
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.625.1
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.637

Related CWEs

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.