CVE-2014-3666: Code Injection
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
Other sources
Jenkins Security Advisory SECURITY-150 notes:
"Unauthenticated user execute arbitrary code on Jenkins master by sending carefully crafted packets over the communication channel."
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3666?
CVE-2014-3666 has a high severity rating as it allows unauthenticated remote code execution on Jenkins.
How do I fix CVE-2014-3666?
To address CVE-2014-3666, upgrade Jenkins to version 1.583 or later, or if using LTS, to version 1.565.3 or later.
Who is affected by CVE-2014-3666?
CVE-2014-3666 affects Jenkins versions prior to 1.583 and Jenkins LTS versions prior to 1.565.3.
Can CVE-2014-3666 exploit be mitigated?
Mitigation for CVE-2014-3666 includes restricting access to the CLI channel and implementing proper authentication and authorization.
Is CVE-2014-3666 a common vulnerability?
CVE-2014-3666 is a recognized vulnerability and is noted in various security advisories due to its potential for widespread impact.