Red Hat Bugzilla – Bug 1147769
CVE-2014-3666 jenkins: remote code execution flaw (SECURITY-150)
Last modified: 2018-06-29 18:02:23 EDT
Jenkins Security Advisory SECURITY-150 notes: "Unauthenticated user execute arbitrary code on Jenkins master by sending carefully crafted packets over the communication channel."
Acknowledgements: Red Hat would like to thank the Jenkins project for reporting this issue. Upstream acknowledges Stephen Connolly as the original reporter.
Public now: https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2014-10-01
This issue has been addressed in the following products: Red Hat OpenShift Enterprise 2.1 Via RHBA-2014:1630 https://rhn.redhat.com/errata/RHBA-2014-1630.html
This issue has been addressed in the following products: RHEL 7 Version of OpenShift Enterprise 3.1 Via RHSA-2016:0070 https://access.redhat.com/errata/RHSA-2016:0070