The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.
References
Configurations
History
21 Nov 2024, 02:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2014/02/21/2 - | |
References | () https://github.com/jenkinsci/jenkins/commit/0530a6645aac10fec005614211660e98db44b5eb - Patch | |
References | () https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2014-02-14 - Vendor Advisory |
Information
Published : 2014-10-17 15:55
Updated : 2024-11-21 02:05
NVD link : CVE-2014-2068
Mitre link : CVE-2014-2068
CVE.ORG link : CVE-2014-2068
JSON object : View
Products Affected
jenkins
- jenkins
CWE
CWE-264
Permissions, Privileges, and Access Controls