CVE-2014-2063: High severity jenkins lts vulnerability
Published Oct 17, 2014
·Updated
Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Affected Software
4 affected componentsFixes available
Jenkins Jenkins<=1.550
Jenkins Jenkins<=1.532.1
maven/org.jenkins-ci.main:jenkins-core<1.532.2
1.532.2
maven/org.jenkins-ci.main:jenkins-core>=1.533<1.551
1.551
Remediation
Event History
Oct 17, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:53 AM
Data Sourced
via GitHub·03:53 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2063?
CVE-2014-2063 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2014-2063?
To fix CVE-2014-2063, upgrade Jenkins to version 1.551 or later.
3
What type of attack does CVE-2014-2063 allow?
CVE-2014-2063 allows attackers to conduct clickjacking attacks.
4
Which versions of Jenkins are affected by CVE-2014-2063?
CVE-2014-2063 affects Jenkins versions before 1.551 and LTS versions before 1.532.2.
5
Is there a workaround for CVE-2014-2063 if I cannot upgrade?
There is no official workaround for CVE-2014-2063, so upgrading is recommended.