CVE-2014-2062
- EPSS 0.19%
- Veröffentlicht 17.10.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
CVE-2014-2063
- EPSS 0.43%
- Veröffentlicht 17.10.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
- EPSS 0.39%
- Veröffentlicht 17.10.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.
CVE-2014-2065
- EPSS 0.14%
- Veröffentlicht 17.10.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to inject arbitrary web script or HTML via the iconSize cookie.
CVE-2014-2066
- EPSS 0.14%
- Veröffentlicht 17.10.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
CVE-2014-2068
- EPSS 0.09%
- Veröffentlicht 17.10.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.
- EPSS 0.07%
- Veröffentlicht 16.10.2014 19:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
CVE-2014-3666
- EPSS 1.21%
- Veröffentlicht 16.10.2014 19:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
- EPSS 0.06%
- Veröffentlicht 16.10.2014 19:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
- EPSS 0.08%
- Veröffentlicht 16.10.2014 19:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.