Back

MEDIUM

jenkins: Ephemeral user record creation

Published Jan 9, 2019

Description

A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Jan 9, 2019
Updated Aug 5, 2024
Reserved Jan 9, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 10, 2018
Bugzilla 1642884

ENISA EUVD

Assigner mitre
Published Jan 9, 2019
Updated Aug 5, 2024