Description
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3451 | The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts. |
Github GHSA |
GHSA-9vg9-x38g-9hfx | Jenkins allows attackers to determine whether a user exists |
References
History
No history.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-06T09:58:16.205Z
Reserved: 2014-02-19T00:00:00.000Z
Link: CVE-2014-2064
No data.
Status : Modified
Published: 2014-10-17T15:55:05.727
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-2064
OpenCVE Enrichment
No data.
EUVD
Github GHSA