CVE-2012-6072

CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
cloudbeesjenkins
1.447.1.1
cloudbeesjenkins
1.447.2.2
cloudbeesjenkins
1.447.3.1
cloudbeesjenkins
1.400
cloudbeesjenkins
1.424
cloudbeesjenkins
1.447
jenkinsjenkins
𝑥
≤ 1.466.2
jenkinsjenkins
1.409.1
jenkinsjenkins
1.409.2
jenkinsjenkins
1.409.3
jenkinsjenkins
1.424.1
jenkinsjenkins
1.424.2
jenkinsjenkins
1.424.3
jenkinsjenkins
1.424.4
jenkinsjenkins
1.424.5
jenkinsjenkins
1.424.6
jenkinsjenkins
1.447.1
jenkinsjenkins
1.447.2
jenkinsjenkins
1.466.1
cloudbeesjenkins
1.466.1.2
cloudbeesjenkins
1.466.2.1
cloudbeesjenkins
𝑥
≤ 1.480.3.1
jenkinsjenkins
1.400
jenkinsjenkins
1.401
jenkinsjenkins
1.402
jenkinsjenkins
1.403
jenkinsjenkins
1.404
jenkinsjenkins
1.405
jenkinsjenkins
1.406
jenkinsjenkins
1.407
jenkinsjenkins
1.408
jenkinsjenkins
1.409
jenkinsjenkins
1.410
jenkinsjenkins
1.411
jenkinsjenkins
1.412
jenkinsjenkins
1.413
jenkinsjenkins
1.414
jenkinsjenkins
1.415
jenkinsjenkins
1.416
jenkinsjenkins
1.417
jenkinsjenkins
1.418
jenkinsjenkins
1.419
jenkinsjenkins
1.420
jenkinsjenkins
1.421
jenkinsjenkins
1.422
jenkinsjenkins
1.423
jenkinsjenkins
1.424
jenkinsjenkins
1.425
jenkinsjenkins
1.426
jenkinsjenkins
1.427
jenkinsjenkins
1.428
jenkinsjenkins
1.429
jenkinsjenkins
1.430
jenkinsjenkins
1.431
jenkinsjenkins
1.432
jenkinsjenkins
1.433
jenkinsjenkins
1.434
jenkinsjenkins
1.435
jenkinsjenkins
1.436
jenkinsjenkins
1.437
cloudbeesjenkins
1.424.0.2
cloudbeesjenkins
1.424.0.4
cloudbeesjenkins
1.424.1.1
cloudbeesjenkins
1.424.2.1
cloudbeesjenkins
1.424.4.1
cloudbeesjenkins
1.424.5.1
cloudbeesjenkins
1.424.6.1
cloudbeesjenkins
1.424.6.11
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jenkins
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
oneiric
ignored
lucid
dne
hardy
dne
jenkins-winstone
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
ignored
vivid
ignored
utopic
ignored
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
oneiric
ignored
lucid
dne
hardy
dne