Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-1000408
HistoryJan 09, 2019 - 11:29 p.m.

Denial of service

2019-01-0923:29:00
PRIOn knowledge base
www.prio-n.com
3

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.2%

A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.

CPENameOperatorVersion
jenkinsle2.138.1
jenkinsle2.145

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.2%