Description
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials.
Remediation
References
Related Vulnerabilities
WordPress Plugin Fancy Product Designer-WooCommerce Arbitrary File Upload (4.6.8)
WordPress Plugin GA Google Analytics Cross-Site Scripting (20210211)
WordPress Plugin Invoicing with InvoiceXpress for WooCommerce-Free Cross-Site Scripting (3.0.2)
WordPress Plugin MapSVG Lite Arbitrary File Disclosure (4.2.3.1)