CVE-2018-1999043: High severity Jenkins Jenkins vulnerability
Published Aug 23, 2018
·Updated
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials.
Affected Software
2 affected components
Jenkins Jenkins<=2.121.2
Jenkins Jenkins<=2.137
Event History
Aug 23, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1999043?
CVE-2018-1999043 is classified as a denial of service vulnerability.
2
How do I fix CVE-2018-1999043?
To mitigate CVE-2018-1999043, upgrade Jenkins to version 2.138 or later.
3
What versions of Jenkins are affected by CVE-2018-1999043?
CVE-2018-1999043 affects Jenkins versions 2.137 and earlier, and 2.121.2 and earlier.
4
What impact does CVE-2018-1999043 have on Jenkins users?
CVE-2018-1999043 allows attackers to create ephemeral in-memory user records, potentially leading to denial of service.
5
Can CVE-2018-1999043 be exploited remotely?
Yes, CVE-2018-1999043 can be exploited remotely by sending numerous invalid login attempts.