CVE-2015-1810

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
16/10/2015
Last modified:
12/04/2025

Description

The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* 1.580.3 (including)
cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:* 3.1 (including)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* 1.599 (including)