CVE-2015-1814
16.10.2015, 20:59
The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.Enginsight
| Vendor | Product | Version |
|---|---|---|
| jenkins | jenkins | 1.596.1 |
| redhat | openshift | 𝑥 ≤ 3.1 |
| jenkins | jenkins | 𝑥 ≤ 1.605 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References