6.5

CVE-2015-5323

Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Openshift SwEdition enterprise Version <= 3.1
Redhat ≫ Openshift Version 2.0
Jenkins ≫ Jenkins SwEdition lts Version <= 1.625.1
Jenkins ≫ Jenkins Version <= 1.637
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.708
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://access.redhat.com/errata/RHSA-2016:0070
http://rhn.redhat.com/errata/RHSA-2016-0489.html
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
Vendor Advisory