Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3665

Опубликовано: 25 нояб. 2015
Источник: debian

Описание

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jenkinsremovedpackage
jenkinsno-dsajessiepackage

Примечания

  • For jessie, the backport is too intrusive and since it's a cornercase, it's only documented,

  • https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2014-10-30

Связанные уязвимости

ubuntu
около 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

redhat
больше 11 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

nvd
около 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

github
больше 3 лет назад

Jenkins improperly ensures trust separation