Description
Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2725 | Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave. |
Github GHSA |
GHSA-66cr-6whx-732p | Jenkins improperly ensures trust separation |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:50:18.303Z
Reserved: 2014-05-14T00:00:00.000Z
Link: CVE-2014-3665
No data.
Status : Modified
Published: 2015-11-25T20:59:00.190
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-3665
OpenCVE Enrichment
No data.
EUVD
Github GHSA