CVE-2014-2061: Medium severity jenkins lts vulnerability
Published Oct 17, 2014
·Updated
The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to obtain passwords by reading the HTML source code, related to the default value.
Affected Software
4 affected componentsFixes available
maven/org.jenkins-ci.main:jenkins-core<1.532.2
1.532.2
maven/org.jenkins-ci.main:jenkins-core>=1.533<1.551
1.551
Jenkins Jenkins<=1.532.1
Jenkins Jenkins<=1.550
Remediation
Event History
Oct 17, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-2061?
CVE-2014-2061 has a high severity as it allows remote attackers to view sensitive information such as passwords.
2
How do I fix CVE-2014-2061?
To fix CVE-2014-2061, upgrade Jenkins to version 1.551 or later, or LTS version 1.532.2 or later.
3
What software versions are affected by CVE-2014-2061?
CVE-2014-2061 affects Jenkins versions prior to 1.551 and LTS versions before 1.532.2.
4
What type of vulnerabilities are associated with CVE-2014-2061?
CVE-2014-2061 is an information disclosure vulnerability related to password handling.
5
Can CVE-2014-2061 be exploited remotely?
Yes, CVE-2014-2061 can be exploited remotely by attackers who can read the HTML source code.