First published: Tue Sep 30 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift | <=3.1 | |
Jenkins LTS | <1.565.3 | |
Jenkins LTS | <1.583 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3681 has been classified as a medium severity vulnerability due to its potential to allow remote script injection.
To fix CVE-2014-3681, upgrade to Jenkins version 1.583 or later, or LTS version 1.565.3 or later.
CVE-2014-3681 allows attackers to perform cross-site scripting (XSS) attacks, enabling them to inject arbitrary scripts into web pages viewed by users.
Versions of Jenkins earlier than 1.583 and LTS versions before 1.565.3 are affected by CVE-2014-3681.
Yes, the vulnerability also affects Red Hat OpenShift enterprise versions up to and including 3.1.