CVE-2014-2064
17.10.2014, 15:55
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 ≤ 1.532.1 |
jenkins | jenkins | 𝑥 ≤ 1.550 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References