CVE Vulnerabilities

CVE-2014-2061

Published: Oct 17, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to obtain passwords by reading the HTML source code, related to the default value.

Affected Software

NameVendorStart VersionEnd Version
JenkinsJenkins*1.532.1 (including)
Red Hat OpenShift Enterprise 2.1RedHatjenkins-0:1.565.3-1.el6op*
Red Hat OpenShift Enterprise 2.1RedHatjenkins-plugin-openshift-0:0.6.40.1-0.el6op*
Red Hat OpenShift Enterprise 2.1RedHatopenshift-origin-cartridge-jenkins-0:1.20.3.5-1.el6op*
JenkinsUbuntuprecise*
JenkinsUbuntuquantal*
JenkinsUbuntusaucy*
JenkinsUbuntuupstream*

References