[MAVEN:GHSA-VXC6-WVH8-FPXW] Jenkins does not invalidate the API token when a user is deleted

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.

ID
MAVEN:GHSA-VXC6-WVH8-FPXW
Severity
moderate
URL
https://github.com/advisories/GHSA-vxc6-wvh8-fpxw
Published
2022-05-17T03:53:54
(2 years ago)
Modified
2024-03-05T14:37:54
(6 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core < 1.532.2
Fixed pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core = 1.532.2
Affected pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core >= 1.533 < 1.551
Fixed pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core = 1.551
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...