CVE-2015-5323: Jenkins
Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
Affected products
- Jenkins Jenkins: up to and including 1.625.1; up to and including 1.637
- Red Hat Openshift: up to and including 3.1; version 2.0 only
Published 2015-11-25. Last modified 2026-06-17.