Lucene search

K
cve[email protected]CVE-2014-2061
HistoryOct 17, 2014 - 3:55 p.m.

CVE-2014-2061

2014-10-1715:55:05
CWE-310
web.nvd.nist.gov
29
cve-2014-2061
jenkins
input control
passwordparameterdefinition
remote attackers
passwords
html
security vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

9.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.8%

The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to obtain passwords by reading the HTML source code, related to the default value.

Affected configurations

NVD
Node
jenkinsjenkinsRange1.532.1lts
Node
jenkinsjenkinsRange1.550
CPENameOperatorVersion
jenkins:jenkinsjenkinsle1.532.1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

9.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.8%