CVE-2015-1814: High severity Jenkins Jenkins vulnerability
The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.
Other sources
The part of Jenkins that issues a new API token was not adequately protected against anonymous attackers. This allows an attacker to escalate privileges on Jenkins
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-03-23
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1814?
CVE-2015-1814 is considered a medium severity vulnerability due to its potential to allow unauthorized privilege escalation.
How do I fix CVE-2015-1814?
The recommended fix for CVE-2015-1814 is to upgrade Jenkins to version 1.606 or later, or LTS version 1.596.2 or later.
What systems are affected by CVE-2015-1814?
CVE-2015-1814 affects Jenkins versions prior to 1.606 and LTS versions prior to 1.596.2.
What type of attacks does CVE-2015-1814 allow?
CVE-2015-1814 allows remote attackers to gain privileges through a forced API token change involving anonymous users.
Is there a workaround for CVE-2015-1814?
There are no official workarounds for CVE-2015-1814; upgrading is the only secure solution.