Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-1810
HistoryOct 16, 2015 - 12:00 a.m.

CVE-2015-1810

2015-10-1600:00:00
ubuntu.com
ubuntu.com
6

4.6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

0.003 Low

EPSS

Percentile

66.3%

The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before
1.596.1 does not restrict access to reserved names when using the “Jenkins’
own user database” setting, which allows remote attackers to gain
privileges by creating a reserved name.

Bugs

4.6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

0.003 Low

EPSS

Percentile

66.3%