CVE-2013-2034: Cloudbees Jenkins

Medium severity, CVSS 6.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code or (2) initiate deployment of binaries to a Maven repository via unspecified vectors.

Affected products

  • Cloudbees Jenkins: up to and including 1.513; version 1.466 only; version 1.480 only; version 1.509 only

Published 2014-05-14. Last modified 2026-06-16.