Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3665

Опубликовано: 25 нояб. 2015
Источник: debian
EPSS Низкий

Описание

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jenkinsremovedpackage
jenkinsno-dsajessiepackage

Примечания

  • For jessie, the backport is too intrusive and since it's a cornercase, it's only documented,

  • https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2014-10-30

EPSS

Процентиль: 83%
0.02502
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

redhat
почти 12 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

nvd
больше 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

github
около 4 лет назад

Jenkins improperly ensures trust separation

EPSS

Процентиль: 83%
0.02502
Низкий