CVE Vulnerabilities

CVE-2014-2058

Published: Oct 17, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary jobs by configuring a job to trigger another job. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7330.

Affected Software

NameVendorStart VersionEnd Version
JenkinsJenkins*1.532.1 (including)
JenkinsUbuntuprecise*
JenkinsUbuntuquantal*
JenkinsUbuntusaucy*
JenkinsUbuntuupstream*

References