Required CVE Record Information
Description
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- rhn.redhat.com: RHSA-2016:0489 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2016:0070 vendor-advisoryx_transferred
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11 x_transferred