TROYANOSYVIRUS
Back to CVEs

CVE-2015-1810

N/A

Description

The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.

CVE Details

CVSS v3.1 ScoreN/A
Published10/16/2015
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0

Affected Products

jenkins:jenkinsredhat:openshift

Weaknesses (CWE)

CWE-264

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.