CVE-2014-2066

Jenkins <1.551-1.532.2 - Info Disclosure

Title source: llm

Description

Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.

Scores

EPSS 0.0014
EPSS Percentile 33.5%

Classification

CWE
CWE-287
Status draft

Affected Products (3)

jenkins/jenkins < 1.532.1
jenkins/jenkins < 1.550
org.jenkins-ci.main/jenkins-core < 1.551Maven

Timeline

Published Oct 17, 2014
Tracked Since Feb 18, 2026