Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-65926
HistoryJun 27, 2022 - 12:00 a.m.

Jenkins user enumeration vulnerability

2022-06-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
30

0.002 Low

EPSS

Percentile

51.4%

Jenkins is a Jenkins open source application. An open source automation server Jenkins provides hundreds of plugins to support building, deploying, and automating any project.Jenkins suffers from a user enumeration vulnerability that stems from an observable time difference between a valid user and an invalid user on the login form. An attacker could exploit the vulnerability by using an invalid user name and making a login attempt with a valid user name and an incorrect password.