CVE-2014-2062: Medium severity jenkins lts vulnerability
Published Oct 17, 2014
·Updated
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
Affected Software
4 affected componentsFixes available
maven/org.jenkins-ci.main:jenkins-core<1.532.2
1.532.2
maven/org.jenkins-ci.main:jenkins-core>=1.533<1.551
1.551
Jenkins Jenkins<=1.532.1
Jenkins Jenkins<=1.550
Remediation
Event History
Oct 17, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-2062?
CVE-2014-2062 is classified as a moderate severity vulnerability due to the risk of unauthorized access.
2
How do I fix CVE-2014-2062?
To fix CVE-2014-2062, upgrade Jenkins to version 1.551 or later.
3
What does CVE-2014-2062 affect?
CVE-2014-2062 affects Jenkins versions prior to 1.551 and LTS versions before 1.532.2.
4
What is the impact of CVE-2014-2062?
The impact of CVE-2014-2062 allows remote authenticated users to retain access via the API token even after a user is deleted.
5
Is CVE-2014-2062 a known exploit?
Yes, CVE-2014-2062 has been documented and it highlights the need for immediate patching.