CVE-2015-5323
published 2015-11-25CVE-2015-5323: Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run…
PriorityP434medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.49%
71.4th percentile
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 1.625.1 | — |
| jenkins | jenkins | <= 1.637 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| redhat | openshift | <= 3.1 | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins allows Administrators to Access API Tokens
ghsa·2022-05-13
CVE-2015-5323 [MEDIUM] CWE-522 Jenkins allows Administrators to Access API Tokens
Jenkins allows Administrators to Access API Tokens
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
OSV
Jenkins allows Administrators to Access API Tokens
osv·2022-05-13
CVE-2015-5323 [MEDIUM] Jenkins allows Administrators to Access API Tokens
Jenkins allows Administrators to Access API Tokens
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
Jenkins
Jenkins Security Advisory 2015-11-11
vendor_jenkins·2015-11-11·CVSS 7.5
CVE-2014-3665 [HIGH] Jenkins Security Advisory 2015-11-11
Title: Jenkins Security Advisory 2015-11-11
Jenkins Security Advisory 2015-11-11
This advisory announces multiple vulnerabilities in Jenkins.
Description
Project name disclosure via fingerprints
SECURITY-153 / CVE-2015-5317
The Jenkins UI allowed users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages if those shared file fingerprints with fingerprinted files in accessible jobs.
Public value used for CSRF protection salt
SECURITY-169 / CVE-2015-5318
The salt used to generate the CSRF protection tokens was a publicly accessible value, allowing malicious users to circumvent CSRF protection by generating the correct token.
XXE injection into job configurations via CLI
SECURITY-173 / CVE-20
Red Hat
jenkins: API tokens of other users available to admins (SECURITY-200)
vendor_redhat·2015-11-11·CVSS 6.5
CVE-2015-5323 [MEDIUM] jenkins: API tokens of other users available to admins (SECURITY-200)
jenkins: API tokens of other users available to admins (SECURITY-200)
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-0489.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11http://rhn.redhat.com/errata/RHSA-2016-0489.htmlhttps://access.redhat.com/errata/RHSA-2016:0070https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
2015-11-25
Published