Description
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
Remediation
References
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2014-10-01
https://access.redhat.com/errata/RHSA-2016:0070
Related Vulnerabilities
CVE-2020-27178 Vulnerability in maven package org.apereo.cas:cas-server-support-otp-mfa-core
CVE-2020-1698 Vulnerability in maven package org.keycloak:keycloak-authz-client
CVE-2021-28657 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2012-2379 Vulnerability in maven package org.apache.cxf:cxf-bundle
CVE-2020-2185 Vulnerability in maven package org.jenkins-ci.plugins:ec2