CVE-2014-2058: Jenkins

Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.

BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary jobs by configuring a job to trigger another job. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7330.

Affected products

  • Jenkins Jenkins: up to and including 1.532.1; up to and including 1.550

Published 2014-10-17. Last modified 2026-06-17.