Description
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials.
Remediation
References
Related Vulnerabilities
WordPress Plugin uCare-Support Ticket System Cross-Site Scripting (1.2.1)
EspoCRM Cleartext Transmission of Sensitive Information Vulnerability (CVE-2022-38846)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-2202)
WordPress Plugin Admin renamer extended Cross-Site Request Forgery (3.2.1)