First published: Fri Oct 17 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to inject arbitrary web script or HTML via the iconSize cookie.
Credit: security@debian.org security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <=1.532.1 | |
Jenkins Jenkins | <=1.550 | |
maven/org.jenkins-ci.main:jenkins-core | <1.532.2 | 1.532.2 |
maven/org.jenkins-ci.main:jenkins-core | >=1.533<1.551 | 1.551 |
<=1.532.1 | ||
<=1.550 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2065 is classified as a high severity vulnerability due to its potential for exploit via cross-site scripting (XSS).
To fix CVE-2014-2065, upgrade Jenkins to version 1.551 or later, or to LTS version 1.532.2 or later.
CVE-2014-2065 affects Jenkins versions prior to 1.551 and LTS versions prior to 1.532.2.
CVE-2014-2065 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts.
Yes, CVE-2014-2065 can be exploited remotely by attackers to inject harmful scripts through the iconSize cookie.