jenkins: Ephemeral user record creation
Published Jan 9, 2019
6.5
MEDIUMCVSS 3.0
EPSS 1.47%
Description
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 3.11
atomic-enterprise-service-catalog-1:3.11.51-1.git.1671.2d16650.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.51-1.git.0.1560686.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-cluster-autoscaler-0:3.11.51-1.git.0.0aa9fc2.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-descheduler-0:3.11.51-1.git.300.89070e8.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-dockerregistry-0:3.11.51-1.git.446.d29ce0e.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-metrics-server-0:3.11.51-1.git.52.03e3a91.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-node-problem-detector-0:3.11.51-1.git.254.22189b0.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-service-idler-0:3.11.51-1.git.14.813574a.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-web-console-0:3.11.51-1.git.324.0ae64ed.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
cri-o-0:1.11.10-1.rhaos3.11.git42c86f0.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
golang-github-openshift-oauth-proxy-0:3.11.51-1.git.419.1af74df.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-alertmanager-0:3.11.51-1.git.0.50a0687.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-node_exporter-0:3.11.51-1.git.1063.12dd8be.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-prometheus-0:3.11.51-1.git.5023.0ad933c.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.138.2.1542054911-1.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins-0:3.11.1542061886-1.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
kibana-0:5.6.13-1.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-ansible-0:3.11.51-2.git.0.51c90a3.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-autoheal-0:3.11.51-1.git.219.8ea4275.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-cluster-capacity-0:3.11.51-1.git.380.ffa21af.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-monitor-project-lifecycle-0:3.11.51-1.git.59.7b59e29.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-monitor-sample-app-0:3.11.51-1.git.5.f6d0188.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.10
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.4
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.5
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.6
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.7
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.9
jenkins
Will not fix
Red Hat OpenShift Container Platform 4
jenkins
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-enterprise-service-catalog-1:3.11.51-1.git.1671.2d16650.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.51-1.git.0.1560686.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler-0:3.11.51-1.git.0.0aa9fc2.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler-0:3.11.51-1.git.300.89070e8.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry-0:3.11.51-1.git.446.d29ce0e.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-metrics-server-0:3.11.51-1.git.52.03e3a91.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-node-problem-detector-0:3.11.51-1.git.254.22189b0.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-service-idler-0:3.11.51-1.git.14.813574a.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-web-console-0:3.11.51-1.git.324.0ae64ed.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | cri-o-0:1.11.10-1.rhaos3.11.git42c86f0.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-openshift-oauth-proxy-0:3.11.51-1.git.419.1af74df.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-alertmanager-0:3.11.51-1.git.0.50a0687.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-node_exporter-0:3.11.51-1.git.1063.12dd8be.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-prometheus-0:3.11.51-1.git.5023.0ad933c.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.138.2.1542054911-1.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins-0:3.11.1542061886-1.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | kibana-0:5.6.13-1.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-ansible-0:3.11.51-2.git.0.51c90a3.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-autoheal-0:3.11.51-1.git.219.8ea4275.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-cluster-capacity-0:3.11.51-1.git.380.ffa21af.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-monitor-project-lifecycle-0:3.11.51-1.git.59.7b59e29.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-monitor-sample-app-0:3.11.51-1.git.5.f6d0188.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.10 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.4 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.5 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.9 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.securityfocus.com/bid/106532 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-1000408 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1642884 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2382 Advisory
- https://github.com/advisories/GHSA-4h47-h3cr-23wh Advisory
- https://github.com/jenkinsci/jenkins/commit/01157a699f611ca7492e872103ac01526a982cf2
- https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1128 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000408
- https://www.cve.org/CVERecord?id=CVE-2018-1000408
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106532 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-1000408 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1642884 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2382 | Advisory | |
| https://github.com/advisories/GHSA-4h47-h3cr-23wh | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/01157a699f611ca7492e872103ac01526a982cf2 | ||
| https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1128 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000408 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000408 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub