PT-2015-3731 · Cloudbees+1 · Jenkins

Kohsuke

+1

·

Published

2015-11-25

·

Updated

2023-02-13

·

CVE-2014-3665

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 1.587 Jenkins LTS versions prior to 1.580.1
Description The issue is related to improper trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
Recommendations For Jenkins versions prior to 1.587, update to version 1.587 or later. For Jenkins LTS versions prior to 1.580.1, update to version 1.580.1 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3665
GHSA-66CR-6WHX-732P

Affected Products

Jenkins