PT-2018-15222 · Jenkins · Jenkins

Nimrod Stoler

+1

·

Publicado

2018-08-23

·

Atualizado

2022-05-13

·

CVE-2018-1999043

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.137 Jenkins versions prior to 2.121.2
Description A denial of service issue exists that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials, specifically affecting files BasicAuthenticationFilter.java and BasicHeaderApiTokenAuthenticator.java.
Recommendations For versions prior to 2.137, update to a version that includes the fix for this issue. For versions prior to 2.121.2, update to a version that includes the fix for this issue.

Correção

DoS

Missing Release of Resource after Effective Lifetime

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1999043
GHSA-2632-H32J-6RG9

Produtos afetados

Jenkins