Description
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.
Remediation
References
https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1128
http://www.securityfocus.com/bid/106532
Related Vulnerabilities
CVE-2022-25350 Vulnerability in npm package puppet-facter
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2022-31139 Vulnerability in maven package io.github.karlatemp:unsafe-accessor
CVE-2022-29078 Vulnerability in npm package ejs
CVE-2010-1330 Vulnerability in maven package org.jruby.jcodings:jcodings