PT-2014-4468 · Cloudbees+1 · Cloudbees Jenkins+1

Published

2014-10-17

·

Updated

2022-05-17

·

CVE-2014-2068

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CloudBees Jenkins versions prior to 1.551 CloudBees Jenkins LTS versions prior to 1.532.2
Description The issue allows remote authenticated users with the ADMINISTER permission to obtain sensitive information. This is related to the doIndex function in hudson/util/RemotingDiagnostics.java and involves vectors related to heap dump.
Recommendations For CloudBees Jenkins versions prior to 1.551, update to version 1.551 or later. For CloudBees Jenkins LTS versions prior to 1.532.2, update to version 1.532.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2068
GHSA-PV88-J6RG-R56P

Affected Products

Cloudbees Jenkins
Jenkins