Vulnerabilities > CVE-2014-3661 - Resource Management Errors vulnerability in multiple products

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.

Vulnerable Configurations

Part Description Count
Application
Redhat
11
Application
Jenkins
1215

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2016-0070.NASL
    descriptionRed Hat OpenShift Enterprise release 3.1.1 is now available with updates to packages that fix several security issues, bugs and introduce feature enhancements. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. OpenShift Enterprise by Red Hat is the company
    last seen2020-06-01
    modified2020-06-02
    plugin id119442
    published2018-12-06
    reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/119442
    titleRHEL 7 : openshift (RHSA-2016:0070)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_549A277149CC11E4AE2CC80AA9043978.NASL
    descriptionJenkins Security Advisory : Please reference CVE/URL list for details
    last seen2020-06-01
    modified2020-06-02
    plugin id78017
    published2014-10-02
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/78017
    titleFreeBSD : jenkins -- remote execution, privilege escalation, XSS, password exposure, ACL hole, DoS (549a2771-49cc-11e4-ae2c-c80aa9043978)
  • NASL familyCGI abuses
    NASL idJENKINS_1_583.NASL
    descriptionThe remote web server hosts a version of Jenkins (open source) or CloudBees Jenkins Enterprise that is affected by multiple vulnerabilities : - An error exists related to file upload processing that allows a remote attacker to overwrite arbitrary files. (CVE-2013-2186) - An input validation error exists related to the included
    last seen2020-06-01
    modified2020-06-02
    plugin id78859
    published2014-11-04
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/78859
    titleJenkins < 1.583 / 1.565.3 and Jenkins Enterprise 1.532.x / 1.554.x / 1.565.x < 1.532.10.1 / 1.554.10.1 / 1.565.3.1 Multiple Vulnerabilities

Redhat

advisories
rhsa
idRHSA-2016:0070
rpms
  • jenkins-0:1.565.3-1.el6op
  • jenkins-plugin-openshift-0:0.6.40.1-0.el6op
  • openshift-origin-cartridge-jenkins-0:1.20.3.5-1.el6op
  • atomic-openshift-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-clients-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-clients-redistributable-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-dockerregistry-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-master-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-node-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-pod-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-recycle-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-sdn-ovs-0:3.1.1.6-1.git.0.b57e8bd.el7aos
  • atomic-openshift-utils-0:3.0.35-1.git.0.6a386dd.el7aos
  • heapster-0:0.18.2-3.gitaf4752e.el7aos
  • jenkins-0:1.625.3-2.el7aos
  • nodejs-align-text-0:0.1.3-2.el7aos
  • nodejs-ansi-green-0:0.1.1-1.el7aos
  • nodejs-ansi-wrap-0:0.1.0-1.el7aos
  • nodejs-anymatch-0:1.3.0-1.el7aos
  • nodejs-arr-diff-0:2.0.0-1.el7aos
  • nodejs-arr-flatten-0:1.0.1-1.el7aos
  • nodejs-array-unique-0:0.2.1-1.el7aos
  • nodejs-arrify-0:1.0.0-1.el7aos
  • nodejs-async-each-0:1.0.0-1.el7aos
  • nodejs-binary-extensions-0:1.3.1-1.el7aos
  • nodejs-braces-0:1.8.2-2.el7aos
  • nodejs-capture-stack-trace-0:1.0.0-2.el7aos
  • nodejs-chokidar-0:1.4.1-2.el7aos
  • nodejs-configstore-0:1.4.0-1.el7aos
  • nodejs-create-error-class-0:2.0.1-2.el7aos
  • nodejs-deep-extend-0:0.3.2-2.el7aos
  • nodejs-duplexer-0:0.1.1-2.el7aos
  • nodejs-duplexify-0:3.4.2-1.el7aos
  • nodejs-end-of-stream-0:1.1.0-2.el7aos
  • nodejs-error-ex-0:1.2.0-1.el7aos
  • nodejs-es6-promise-0:3.0.2-2.el7aos
  • nodejs-event-stream-0:3.3.2-1.el7aos
  • nodejs-expand-brackets-0:0.1.4-1.el7aos
  • nodejs-expand-range-0:1.8.1-1.el7aos
  • nodejs-extglob-0:0.3.1-1.el7aos
  • nodejs-filename-regex-0:2.0.0-1.el7aos
  • nodejs-fill-range-0:2.2.3-1.el7aos
  • nodejs-for-in-0:0.1.4-1.el7aos
  • nodejs-for-own-0:0.1.3-1.el7aos
  • nodejs-from-0:0.1.3-2.el7aos
  • nodejs-glob-base-0:0.3.0-1.el7aos
  • nodejs-glob-parent-0:2.0.0-1.el7aos
  • nodejs-got-0:5.2.1-1.el7aos
  • nodejs-graceful-fs-0:4.1.2-1.el7aos
  • nodejs-ini-0:1.1.0-6.el7aos
  • nodejs-is-binary-path-0:1.0.1-1.el7aos
  • nodejs-is-dotfile-0:1.0.2-1.el7aos
  • nodejs-is-equal-shallow-0:0.1.3-1.el7aos
  • nodejs-is-extendable-0:0.1.1-1.el7aos
  • nodejs-is-extglob-0:1.0.0-1.el7aos
  • nodejs-is-glob-0:2.0.1-1.el7aos
  • nodejs-is-npm-0:1.0.0-1.el7aos
  • nodejs-is-number-0:2.1.0-1.el7aos
  • nodejs-is-plain-obj-0:1.0.0-1.el7aos
  • nodejs-is-primitive-0:2.0.0-1.el7aos
  • nodejs-is-redirect-0:1.0.0-1.el7aos
  • nodejs-is-stream-0:1.0.1-2.el7aos
  • nodejs-isobject-0:2.0.0-1.el7aos
  • nodejs-kind-of-0:3.0.2-1.el7aos
  • nodejs-latest-version-0:2.0.0-1.el7aos
  • nodejs-lazy-cache-0:1.0.2-1.el7aos
  • nodejs-lodash.assign-0:3.2.0-1.el7aos
  • nodejs-lodash.baseassign-0:3.2.0-1.el7aos
  • nodejs-lodash.basecopy-0:3.0.1-1.el7aos
  • nodejs-lodash.bindcallback-0:3.0.1-1.el7aos
  • nodejs-lodash.createassigner-0:3.1.1-1.el7aos
  • nodejs-lodash.defaults-0:3.1.2-1.el7aos
  • nodejs-lodash.getnative-0:3.9.1-1.el7aos
  • nodejs-lodash.isarguments-0:3.0.4-1.el7aos
  • nodejs-lodash.isarray-0:3.0.4-1.el7aos
  • nodejs-lodash.isiterateecall-0:3.0.9-1.el7aos
  • nodejs-lodash.keys-0:3.1.2-1.el7aos
  • nodejs-lodash.restparam-0:3.6.1-1.el7aos
  • nodejs-lowercase-keys-0:1.0.0-2.el7aos
  • nodejs-map-stream-0:0.1.0-2.el7aos
  • nodejs-micromatch-0:2.3.5-2.el7aos
  • nodejs-mkdirp-0:0.5.0-2.el7aos
  • nodejs-node-status-codes-0:1.0.0-1.el7aos
  • nodejs-nodemon-0:1.8.1-2.el7aos
  • nodejs-normalize-path-0:2.0.1-1.el7aos
  • nodejs-object-assign-0:4.0.1-1.el7aos
  • nodejs-object.omit-0:2.0.0-1.el7aos
  • nodejs-optimist-0:0.4.0-5.el7aos
  • nodejs-os-homedir-0:1.0.1-1.el7aos
  • nodejs-os-tmpdir-0:1.0.1-1.el7aos
  • nodejs-osenv-0:0.1.0-2.el7aos
  • nodejs-package-json-0:2.3.0-1.el7aos
  • nodejs-parse-glob-0:3.0.4-1.el7aos
  • nodejs-parse-json-0:2.2.0-2.el7aos
  • nodejs-pause-stream-0:0.0.11-2.el7aos
  • nodejs-pinkie-0:2.0.1-1.el7aos
  • nodejs-pinkie-promise-0:2.0.0-1.el7aos
  • nodejs-prepend-http-0:1.0.1-2.el7aos
  • nodejs-preserve-0:0.2.0-1.el7aos
  • nodejs-ps-tree-0:1.0.1-1.el7aos
  • nodejs-randomatic-0:1.1.5-1.el7aos
  • nodejs-rc-0:1.1.2-1.el7aos
  • nodejs-read-all-stream-0:3.0.1-3.el7aos
  • nodejs-readdirp-0:2.0.0-2.el7aos
  • nodejs-regex-cache-0:0.4.2-1.el7aos
  • nodejs-registry-url-0:3.0.3-1.el7aos
  • nodejs-repeat-element-0:1.1.2-1.el7aos
  • nodejs-semver-0:5.1.0-1.el7aos
  • nodejs-semver-diff-0:2.1.0-1.el7aos
  • nodejs-slide-0:1.1.5-3.el7aos
  • nodejs-split-0:0.3.3-2.el7aos
  • nodejs-stream-combiner-0:0.2.1-2.el7aos
  • nodejs-string-length-0:1.0.1-1.el7aos
  • nodejs-strip-json-comments-0:1.0.2-2.el7aos
  • nodejs-success-symbol-0:0.1.0-1.el7aos
  • nodejs-through-0:2.3.4-4.el7aos
  • nodejs-timed-out-0:2.0.0-3.el7aos
  • nodejs-touch-0:1.0.0-2.el7aos
  • nodejs-undefsafe-0:0.0.3-1.el7aos
  • nodejs-unzip-response-0:1.0.0-1.el7aos
  • nodejs-update-notifier-0:0.6.0-1.el7aos
  • nodejs-url-parse-lax-0:1.0.0-1.el7aos
  • nodejs-uuid-0:2.0.1-1.el7aos
  • nodejs-write-file-atomic-0:1.1.2-2.el7aos
  • nodejs-xdg-basedir-0:2.0.0-1.el7aos
  • nss_wrapper-0:1.0.3-1.el7
  • nss_wrapper-debuginfo-0:1.0.3-1.el7
  • openshift-ansible-0:3.0.35-1.git.0.6a386dd.el7aos
  • openshift-ansible-docs-0:3.0.35-1.git.0.6a386dd.el7aos
  • openshift-ansible-filter-plugins-0:3.0.35-1.git.0.6a386dd.el7aos
  • openshift-ansible-lookup-plugins-0:3.0.35-1.git.0.6a386dd.el7aos
  • openshift-ansible-playbooks-0:3.0.35-1.git.0.6a386dd.el7aos
  • openshift-ansible-roles-0:3.0.35-1.git.0.6a386dd.el7aos
  • openvswitch-0:2.4.0-1.el7
  • openvswitch-debuginfo-0:2.4.0-1.el7
  • openvswitch-devel-0:2.4.0-1.el7
  • openvswitch-test-0:2.4.0-1.el7
  • origin-kibana-0:0.5.0-1.el7aos
  • python-openvswitch-0:2.4.0-1.el7
  • tuned-profiles-atomic-openshift-node-0:3.1.1.6-1.git.0.b57e8bd.el7aos