A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1912 A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials.
Github GHSA Github GHSA GHSA-2632-h32j-6rg9 Missing Release of Resource after Effective Lifetime in Jenkins
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T18:03:50.826Z

Reserved: 2018-08-23T00:00:00Z

Link: CVE-2018-1999043

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-23T18:29:00.577

Modified: 2024-11-21T03:57:07.597

Link: CVE-2018-1999043

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-08-15T00:00:00Z

Links: CVE-2018-1999043 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses