Jenkins Multiple Remote Security Vulnerabilities
BID:65694
Info
Jenkins Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 65694 |
| Class: | Unknown |
| CVE: |
CVE-2014-2059 CVE-2014-2060 CVE-2014-2061 CVE-2014-2062 CVE-2014-2063 CVE-2014-2064 CVE-2014-2065 CVE-2014-2066 CVE-2014-2067 CVE-2014-2068 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2014 12:00AM |
| Updated: | Mar 11 2014 01:23AM |
| Credit: | Reported by the vendor. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Jenkins Multiple Remote Security Vulnerabilities
Jenkins is prone to multiple security vulnerabilities:
1. An HTML-injection vulnerability
2. A session-fixation vulnerability
3. A cross-site scripting vulnerability
4. A user-enumeration weakness
5. A click-jacking vulnerability
6. Multiple security-bypass vulnerabilities
7. Multiple information-disclosure vulnerabilities
8. A directory-traversal vulnerability
An attacker may leverage these issues to hijack an arbitrary session, harvest valid usernames, bypass certain security restrictions, execute HTML and arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials or to control how the site is rendered to the user, and obtain sensitive information.
NOTE: The issue (described by CVE-2014-2058) has been moved to BID 65720 (Jenkins BuildTrigger Class CVE-2014-2058 Incomplete Fix Security Bypass Vulnerability) to better document it.
Jenkins is prone to multiple security vulnerabilities:
1. An HTML-injection vulnerability
2. A session-fixation vulnerability
3. A cross-site scripting vulnerability
4. A user-enumeration weakness
5. A click-jacking vulnerability
6. Multiple security-bypass vulnerabilities
7. Multiple information-disclosure vulnerabilities
8. A directory-traversal vulnerability
An attacker may leverage these issues to hijack an arbitrary session, harvest valid usernames, bypass certain security restrictions, execute HTML and arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials or to control how the site is rendered to the user, and obtain sensitive information.
NOTE: The issue (described by CVE-2014-2058) has been moved to BID 65720 (Jenkins BuildTrigger Class CVE-2014-2058 Incomplete Fix Security Bypass Vulnerability) to better document it.
Exploit / POC
Jenkins Multiple Remote Security Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit some of these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
Attackers can use a browser to exploit these issues. To exploit some of these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
Jenkins Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.