CVE-2014-3680: Infoleak
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
Other sources
Jenkins Security Advisory SECURITY-138 notes:
"If a parameterized job has a default value in a password field, that default value gets exposed to users with Job/READ permission."
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3680?
CVE-2014-3680 is rated as a medium severity vulnerability.
How do I fix CVE-2014-3680?
To fix CVE-2014-3680, upgrade Jenkins to version 1.583 or later.
Who is affected by CVE-2014-3680?
CVE-2014-3680 affects Jenkins versions before 1.583 and LTS versions before 1.565.3.
What types of users can exploit CVE-2014-3680?
Remote authenticated users with the Job/READ permission can exploit CVE-2014-3680.
What kind of information is exposed by CVE-2014-3680?
CVE-2014-3680 allows access to the default value of the password field in parameterized jobs.