CVE-2014-3665

Description

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.476

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 1.586Windows
Vulnerabilities CVE-2014-3665 are fixed in Jenkins-Core 1.587Windows
Multiple vulnerabilities affected in Jenkins 1.586 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 1.586 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 1.586 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 1.586 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 1.586 (For Suse)Linux
Vulnerabilities CVE-2014-3665 are fixed in Jenkins-Core for Linux 1.587Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234