Lucene search

K
nvd[email protected]NVD:CVE-2015-5323
HistoryNov 25, 2015 - 8:59 p.m.

CVE-2015-5323

2015-11-2520:59:14
CWE-264
web.nvd.nist.gov
8

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

56.7%

Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.

Affected configurations

Nvd
Node
redhatopenshiftRange3.1enterprise
Node
redhatopenshiftMatch2.0
Node
jenkinsjenkinsRange1.625.1lts
Node
jenkinsjenkinsRange1.637
VendorProductVersionCPE
redhatopenshift*cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:*
redhatopenshift2.0cpe:2.3:a:redhat:openshift:2.0:*:*:*:*:*:*:*
jenkinsjenkins*cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
jenkinsjenkins*cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

56.7%