CVE-2014-3665
Jenkins < 1.587 and LTS < 1.580.1 - Remote Code Execution via Slave to Master Access Control
Title source: llmDescription
Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2014-10-30
Vendor Advisory x_refsource_confirm
https://wiki.jenkins-ci.org/display/JENKINS/Slave+To+Master+Access+Control
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1147767
Vendor Advisory x_refsource_confirm
https://www.cloudbees.com/jenkins-security-advisory-2014-10-30
Scores
EPSS
0.0035
EPSS Percentile
57.8%
Details
CWE
CWE-264
Status
published
Products (3)
jenkins/jenkins
< 1.565.3
jenkins/jenkins
< 1.586
org.jenkins-ci.main/jenkins-core
0 - 1.587Maven
Published
Nov 25, 2015
Tracked Since
Feb 18, 2026