CVE Vulnerabilities

CVE-2015-1810

Published: Oct 16, 2015 | Modified: Jun 15, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the Jenkins own user database setting, which allows remote attackers to gain privileges by creating a reserved name.

Affected Software

Name Vendor Start Version End Version
Jenkins Jenkins * 1.580.3 (including)

References