PT-2014-4468 · Cloudbees+1 · Cloudbees Jenkins+1
Published
2014-10-17
·
Updated
2022-05-17
·
CVE-2014-2068
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CloudBees Jenkins versions prior to 1.551
CloudBees Jenkins LTS versions prior to 1.532.2
Description
The issue allows remote authenticated users with the ADMINISTER permission to obtain sensitive information. This is related to the
doIndex function in hudson/util/RemotingDiagnostics.java and involves vectors related to heap dump.Recommendations
For CloudBees Jenkins versions prior to 1.551, update to version 1.551 or later.
For CloudBees Jenkins LTS versions prior to 1.532.2, update to version 1.532.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudbees Jenkins
Jenkins