- EPSS 1.38%
- Veröffentlicht 16.10.2014 19:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
CVE-2014-3666
- EPSS 3.65%
- Veröffentlicht 16.10.2014 19:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
- EPSS 1.36%
- Veröffentlicht 16.10.2014 19:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
- EPSS 1.36%
- Veröffentlicht 16.10.2014 19:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
- EPSS 1.8%
- Veröffentlicht 16.10.2014 19:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.
- EPSS 1.74%
- Veröffentlicht 16.10.2014 19:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
- EPSS 2.47%
- Veröffentlicht 15.10.2014 14:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.
CVE-2014-3681
- EPSS 2.13%
- Veröffentlicht 15.10.2014 14:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- EPSS 5.09%
- Veröffentlicht 20.06.2014 14:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in...
CVE-2014-0164
- EPSS 0.38%
- Veröffentlicht 05.05.2014 17:06:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information b...