CVE-2014-2062: Jenkins
Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
Affected products
- Jenkins Jenkins: up to and including 1.532.1; up to and including 1.550
Published 2014-10-17. Last modified 2026-06-17.