QID 997973
Date Published: 2024-04-08
QID 997973: Java (Maven) Security Update for org.jenkins-ci.main:jenkins-core (GHSA-9vg9-x38g-9hfx)
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9vg9-x38g-9hfx for updates and patch information.
Vendor References
- GHSA-9vg9-x38g-9hfx -
github.com/advisories/GHSA-9vg9-x38g-9hfx
CVEs related to QID 997973
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9vg9-x38g-9hfx | org.jenkins-ci.main:jenkins-core |
|