Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3665.
{
"nvd_published_at": "2015-11-25T20:59:00Z",
"github_reviewed_at": "2025-03-13T17:52:24Z",
"cwe_ids": [
"CWE-284"
],
"github_reviewed": true,
"severity": "MODERATE"
}