CVE Vulnerabilities

CVE-2014-3665

Published: Nov 25, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

Affected Software

Name Vendor Start Version End Version
Jenkins Jenkins * 1.586 (including)
Red Hat OpenShift Enterprise 2.1 RedHat jenkins-0:1.565.3-1.el6op *
Red Hat OpenShift Enterprise 2.1 RedHat jenkins-plugin-openshift-0:0.6.40.1-0.el6op *
Red Hat OpenShift Enterprise 2.1 RedHat openshift-origin-cartridge-jenkins-0:1.20.3.5-1.el6op *
Jenkins Ubuntu precise *

References