CVE-2018-1000408: Medium severity jenkins lts vulnerability
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000408?
CVE-2018-1000408 has a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2018-1000408?
To fix CVE-2018-1000408, upgrade Jenkins to version 2.146 or later, or LTS version 2.138.2 or later.
Who is affected by CVE-2018-1000408?
CVE-2018-1000408 affects Jenkins versions up to and including 2.145 and LTS versions up to and including 2.138.1.
What kind of vulnerability is CVE-2018-1000408?
CVE-2018-1000408 is a denial of service vulnerability that allows unauthorized access to a specific URL.
What should I do if I cannot upgrade to mitigate CVE-2018-1000408?
If you cannot upgrade, consider restricting access to the Jenkins instance or applying temporary mitigating controls to limit exposure.