Description
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2382 | A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory. |
Github GHSA |
GHSA-4h47-h3cr-23wh | Improper Authorization in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:40:47.039Z
Reserved: 2019-01-09T00:00:00.000Z
Link: CVE-2018-1000408
No data.
Status : Modified
Published: 2019-01-09T23:29:02.340
Modified: 2024-11-21T03:40:00.263
Link: CVE-2018-1000408
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA