Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.
Advisories
Source ID Title
EUVD EUVD EUVD-2012-4371 Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access
Github GHSA Github GHSA GHSA-wr6p-j63r-xqhv Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T20:35:09.455Z

Reserved: 2012-08-21T00:00:00

Link: CVE-2012-4438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-18T21:15:11.340

Modified: 2024-11-21T01:42:53.873

Link: CVE-2012-4438

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-09-17T00:00:00Z

Links: CVE-2012-4438 - Bugzilla

cve-icon OpenCVE Enrichment

No data.