First published: Wed Jan 09 2019(Updated: )
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <=2.138.1 | |
Jenkins Jenkins | <=2.145 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000408 has a medium severity rating due to its potential to cause denial of service.
To fix CVE-2018-1000408, upgrade Jenkins to version 2.146 or later, or LTS version 2.138.2 or later.
CVE-2018-1000408 affects Jenkins versions up to and including 2.145 and LTS versions up to and including 2.138.1.
CVE-2018-1000408 is a denial of service vulnerability that allows unauthorized access to a specific URL.
If you cannot upgrade, consider restricting access to the Jenkins instance or applying temporary mitigating controls to limit exposure.