CVE-2014-2062

EPSS 0.19%

Jenkins does not invalidate the API token when a user is deleted

發布日:2022/5/17修改日:2024/12/3

描述

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.

受影響套件(1)

參考連結(5)