Lack of data validation In org.jenkins-ci.main:jenkins-core
Description
Jenkins improperly ensures trust separation Jenkins prior to 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 1.587 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.