Lucene search

K
osvGoogleOSV:GHSA-VXC6-WVH8-FPXW
HistoryMay 17, 2022 - 3:53 a.m.

Jenkins does not invalidate the API token when a user is deleted

2022-05-1703:53:54
Google
osv.dev
12
jenkins
api token
user deletion
remote access

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

71.4%

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

71.4%