Back to search
CVE-2012-0785
Published: Feb 24, 2020
Modified: Aug 6, 2024
PUBLISHED
Description
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
| Vendor | Product | Versions |
|---|---|---|
Jenkins project | Jenkins | affected before 1.447 |
Jenkins project | Jenkins LTS | affected before 1.424.2 |
Jenkins project | Jenkins Enterprise by CloudBees | affected 1.424.x before 1.424.2.1affected 1.400.x before 1.400.0.11 |
References
[oss-security] 20120119 Re: CVE request: Jenkins
mailing-list
x_refsource_MLIST
https://security-tracker.debian.org/tracker/CVE-2012-0785
x_refsource_MISC
https://access.redhat.com/security/cve/cve-2012-0785
x_refsource_MISC
https://jenkins.io/security/advisory/2012-01-12/
x_refsource_CONFIRM
https://www.cloudbees.com/jenkins-security-advisory-2012-01-12
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now