CVE-2015-1814

Description

The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a forced API token change involving anonymous users.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.239

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 1.605Windows
Vulnerabilities CVE-2015-1813,CVE-2015-1814 are fixed in Jenkins-Core 1.606Windows
Vulnerabilities CVE-2015-1812,CVE-2015-1813,CVE-2015-1814 are fixed in Jenkins-Core 1.596.2Windows
Multiple vulnerabilities affected in Jenkins 1.605 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 1.605 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 1.605 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 1.605 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 1.605 (For Suse)Linux
Vulnerabilities CVE-2015-1813,CVE-2015-1814 are fixed in Jenkins-Core for Linux 1.606Linux
Vulnerabilities CVE-2015-1812,CVE-2015-1813,CVE-2015-1814 are fixed in Jenkins-Core for Linux 1.596.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234