CVE-2015-5298: Medium severity jenkins vulnerability
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-5298?
CVE-2015-5298 is a vulnerability in the Google Login Plugin versions 1.0 and 1.1 for Jenkins that allows malicious anonymous users to bypass security measures.
What software versions are affected by CVE-2015-5298?
The Google Login Plugin versions 1.0 and 1.1 for Jenkins are affected by CVE-2015-5298.
How does CVE-2015-5298 affect Jenkins instances?
CVE-2015-5298 allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain.
What is the severity of CVE-2015-5298?
CVE-2015-5298 has a severity rating of medium with a score of 6.5.
How can I fix CVE-2015-5298?
To fix CVE-2015-5298, it is recommended to update the Google Login Plugin to a secure version.