CVE-2014-2064

EPSS 0.39%

Jenkins allows attackers to determine whether a user exists

發布日:2022/5/17修改日:2024/12/3

描述

The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.

受影響套件(1)

參考連結(5)