CVE Vulnerabilities

CVE-2015-1810

Published: Oct 16, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
4.6 MODERATE
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the Jenkins own user database setting, which allows remote attackers to gain privileges by creating a reserved name.

Affected Software

NameVendorStart VersionEnd Version
JenkinsJenkins*1.580.3 (including)
Red Hat OpenShift Enterprise 2.2RedHatjenkins-0:1.609.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-broker-0:1.16.2.10-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-broker-util-0:1.36.2.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-diy-0:1.26.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-haproxy-0:1.30.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jbosseap-0:2.26.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jbossews-0:1.34.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-jenkins-0:1.28.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-mock-0:1.22.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-nodejs-0:1.33.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-perl-0:1.30.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-php-0:1.34.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-python-0:1.33.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-cartridge-ruby-0:1.32.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-logshifter-0:1.10.1.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatopenshift-origin-node-util-0:1.37.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrhc-0:1.37.1.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-console-0:1.35.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-controller-0:1.37.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-frontend-apache-vhost-0:0.12.4.2-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-gear-placement-0:0.0.2.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-msg-broker-mcollective-0:1.35.3.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-node-0:1.37.1.1-1.el6op*
Red Hat OpenShift Enterprise 2.2RedHatrubygem-openshift-origin-routing-daemon-0:0.25.1.2-1.el6op*
Red Hat OpenShift Enterprise 3.1RedHatatomic-openshift-0:3.1.1.6-1.git.0.b57e8bd.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatheapster-0:0.18.2-3.gitaf4752e.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatjenkins-0:1.625.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-align-text-0:0.1.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ansi-green-0:0.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ansi-wrap-0:0.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-anymatch-0:1.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-array-unique-0:0.2.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arr-diff-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arr-flatten-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-arrify-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-async-each-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-binary-extensions-0:1.3.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-braces-0:1.8.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-capture-stack-trace-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-chokidar-0:1.4.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-configstore-0:1.4.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-create-error-class-0:2.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-deep-extend-0:0.3.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-duplexer-0:0.1.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-duplexify-0:3.4.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-end-of-stream-0:1.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-error-ex-0:1.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-es6-promise-0:3.0.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-event-stream-0:3.3.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-expand-brackets-0:0.1.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-expand-range-0:1.8.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-extglob-0:0.3.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-filename-regex-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-fill-range-0:2.2.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-for-in-0:0.1.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-for-own-0:0.1.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-from-0:0.1.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-glob-base-0:0.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-glob-parent-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-got-0:5.2.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-graceful-fs-0:4.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ini-0:1.1.0-6.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-binary-path-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-dotfile-0:1.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-equal-shallow-0:0.1.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-extendable-0:0.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-extglob-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-glob-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-npm-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-number-0:2.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-isobject-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-plain-obj-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-primitive-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-redirect-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-is-stream-0:1.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-kind-of-0:3.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-latest-version-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lazy-cache-0:1.0.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.assign-0:3.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.baseassign-0:3.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.basecopy-0:3.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.bindcallback-0:3.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.createassigner-0:3.1.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.defaults-0:3.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.getnative-0:3.9.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isarguments-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isarray-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.isiterateecall-0:3.0.9-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.keys-0:3.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lodash.restparam-0:3.6.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-lowercase-keys-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-map-stream-0:0.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-micromatch-0:2.3.5-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-mkdirp-0:0.5.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-nodemon-0:1.8.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-node-status-codes-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-normalize-path-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-object-assign-0:4.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-object.omit-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-optimist-0:0.4.0-5.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-osenv-0:0.1.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-os-homedir-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-os-tmpdir-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-package-json-0:2.3.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-parse-glob-0:3.0.4-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-parse-json-0:2.2.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pause-stream-0:0.0.11-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pinkie-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-pinkie-promise-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-prepend-http-0:1.0.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-preserve-0:0.2.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-ps-tree-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-randomatic-0:1.1.5-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-rc-0:1.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-read-all-stream-0:3.0.1-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-readdirp-0:2.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-regex-cache-0:0.4.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-registry-url-0:3.0.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-repeat-element-0:1.1.2-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-semver-0:5.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-semver-diff-0:2.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-slide-0:1.1.5-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-split-0:0.3.3-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-stream-combiner-0:0.2.1-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-string-length-0:1.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-strip-json-comments-0:1.0.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-success-symbol-0:0.1.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-through-0:2.3.4-4.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-timed-out-0:2.0.0-3.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-touch-0:1.0.0-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-undefsafe-0:0.0.3-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-unzip-response-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-update-notifier-0:0.6.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-url-parse-lax-0:1.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-uuid-0:2.0.1-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-write-file-atomic-0:1.1.2-2.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnodejs-xdg-basedir-0:2.0.0-1.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatnss_wrapper-0:1.0.3-1.el7*
Red Hat OpenShift Enterprise 3.1RedHatopenshift-ansible-0:3.0.35-1.git.0.6a386dd.el7aos*
Red Hat OpenShift Enterprise 3.1RedHatopenvswitch-0:2.4.0-1.el7*
Red Hat OpenShift Enterprise 3.1RedHatorigin-kibana-0:0.5.0-1.el7aos*
JenkinsUbuntuprecise*

References