CVE-2014-2060: Jenkins allows Remote Attackers to Hijack Sessions
(updated )
The Winstone servlet container in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack sessions via unspecified vectors.
References
Detect and mitigate CVE-2014-2060 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →