CVE-2014-2066

CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.72 % (81th)
0.72% Progress
Affected Products 1
Advisories 1

Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.

Weaknesses
CWE-287
Improper Authentication
CVE Status
PUBLISHED
CNA
Debian GNU/Linux
Published Date
2014-10-17 15:55:05
(10 years ago)
Updated Date
2016-06-13 23:40:17
(8 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins 1.532.1 and prior versions cpe:2.3:a:jenkins:jenkins::*:*:*:lts <= 1.532.1

Configuration #2

    CPE23 From Up To
  Jenkins 1.550 and prior versions cpe:2.3:a:jenkins:jenkins <= 1.550
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...