CVE-2014-3665: Jenkins
Medium severity, CVSS 6.8. EPSS: 2.5% chance of exploitation in the next 30 days.
Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
Affected products
- Jenkins Jenkins: up to and including 1.586; up to and including 1.565.3
Published 2015-11-25. Last modified 2026-06-17.