First published: Fri Oct 17 2014(Updated: )
The Winstone servlet container in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack sessions via unspecified vectors.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins | <=1.550 | |
Jenkins | <=1.532.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2060 is considered a high severity vulnerability due to its potential for session hijacking.
To fix CVE-2014-2060, update Jenkins to versions 1.551 or later, or the LTS version 1.532.2 or later.
CVE-2014-2060 affects Jenkins versions prior to 1.551 and LTS versions prior to 1.532.2.
CVE-2014-2060 allows remote attackers to hijack sessions, compromising user authentication.
There are no known workarounds for CVE-2014-2060; the best mitigation is to update to a secure version.