CVE-2014-2068: Jenkins

Low severity, CVSS 3.5. EPSS: 1.4% chance of exploitation in the next 30 days.

The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.

Affected products

  • Jenkins Jenkins: up to and including 1.550; up to and including 1.532.1

Published 2014-10-17. Last modified 2026-06-17.