CVE-2014-2065: XSS
Published Oct 17, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to inject arbitrary web script or HTML via the iconSize cookie.
Affected Software
4 affected componentsFixes available
maven/org.jenkins-ci.main:jenkins-core<1.532.2
1.532.2
maven/org.jenkins-ci.main:jenkins-core>=1.533<1.551
1.551
Jenkins Jenkins<=1.532.1
Jenkins Jenkins<=1.550
Remediation
Event History
Oct 17, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-2065?
CVE-2014-2065 is classified as a high severity vulnerability due to its potential for exploit via cross-site scripting (XSS).
2
How do I fix CVE-2014-2065?
To fix CVE-2014-2065, upgrade Jenkins to version 1.551 or later, or to LTS version 1.532.2 or later.
3
What does CVE-2014-2065 affect?
CVE-2014-2065 affects Jenkins versions prior to 1.551 and LTS versions prior to 1.532.2.
4
What type of vulnerability is CVE-2014-2065?
CVE-2014-2065 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts.
5
Can CVE-2014-2065 be exploited remotely?
Yes, CVE-2014-2065 can be exploited remotely by attackers to inject harmful scripts through the iconSize cookie.