CloudBees Jenkins Elevation of Privilege Vulnerability (CVE-2015-5323)
CloudBees Jenkins Elevation of Privilege Vulnerability (CVE-2015-5323)
Release date:
Updated on:
Affected Systems:
CloudBees Jenkins <LTS 1.625.2
CloudBees Jenkins <1.638
Description:
CVE (CAN) ID: CVE-2015-5323
CloudBees Jenkins is an open-source continuous Integration Server.
CloudBees Jenkins 1.638 and LTS 1.625.2 versions earlier have security vulnerabilities. with API tokens of other users, remote administrators can exploit this vulnerability to obtain elevated permissions to run scripts.
<* Source: Jenkins
Oleg nenasev
*>
Suggestion:
Vendor patch:
CloudBees
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
Https://jenkins-ci.org/content/mitigating-unauthenticated-remote-code-execution-0-day-jenkins-cli
This article permanently updates the link address: