Back to search
CVE-2018-1000408
Published: Jan 9, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1128
x_refsource_CONFIRM
106532
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now