The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.
References
Information
Published : 2014-10-17 08:55
Updated : 2016-06-13 16:43
NVD link : CVE-2014-2068
Mitre link : CVE-2014-2068
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
jenkins
- jenkins