Back

LOW

jenkins: information leak via system diagnostic functionalities (SECURITY-73)

Published Oct 17, 2014

Description

The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner debian
Published Oct 17, 2014
Updated Aug 6, 2024
Reserved Feb 19, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 7, 2014
GHSA-PV88-J6RG-R56P