Cloudbees · Jenkins · CVE-2014-3665
**Name of the Vulnerable Software and Affected Versions**
Jenkins versions prior to 1.587
Jenkins LTS versions prior to 1.580.1
**Description**
The issue is related to improper trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
**Recommendations**
For Jenkins versions prior to 1.587, update to version 1.587 or later.
For Jenkins LTS versions prior to 1.580.1, update to version 1.580.1 or later.