PT-2015-3731 · Cloudbees+1 · Jenkins

Kohsuke

+1

·

Publicado

2015-11-25

·

Atualizado

2023-02-13

·

CVE-2014-3665

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 1.587 Jenkins LTS versions prior to 1.580.1
Description The issue is related to improper trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
Recommendations For Jenkins versions prior to 1.587, update to version 1.587 or later. For Jenkins LTS versions prior to 1.580.1, update to version 1.580.1 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3665
GHSA-66CR-6WHX-732P

Produtos afetados

Jenkins