Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3665

Опубликовано: 30 окт. 2014
Источник: redhat
CVSS2: 6.8

Описание

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1jenkinsWill not fix
Red Hat OpenShift Enterprise 2.1jenkinsFixedRHBA-2014:163014.10.2014
Red Hat OpenShift Enterprise 2.1jenkins-plugin-openshiftFixedRHBA-2014:163014.10.2014
Red Hat OpenShift Enterprise 2.1openshift-origin-cartridge-jenkinsFixedRHBA-2014:163014.10.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-250
https://bugzilla.redhat.com/show_bug.cgi?id=1147767jenkins: remote code execution from slaves (SECURITY-144)

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

nvd
около 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

debian
около 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure tru ...

github
больше 3 лет назад

Jenkins improperly ensures trust separation

6.8 Medium

CVSS2