CVE Vulnerabilities

CVE-2014-3665

Published: Nov 25, 2015 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

Affected Software

Name Vendor Start Version End Version
Jenkins Jenkins * 1.586 (including)
Red Hat OpenShift Enterprise 2.1 RedHat jenkins-0:1.565.3-1.el6op *
Red Hat OpenShift Enterprise 2.1 RedHat jenkins-plugin-openshift-0:0.6.40.1-0.el6op *
Red Hat OpenShift Enterprise 2.1 RedHat openshift-origin-cartridge-jenkins-0:1.20.3.5-1.el6op *
Jenkins Ubuntu precise *

References