CVE-2012-0785: Cloudbees Jenkins

High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

Affected products

  • Cloudbees Jenkins: from 1.400.0, before 1.400.0.11 (fixed in 1.400.0.11); from 1.424.0, before 1.424.2.1 (fixed in 1.424.2.1)
  • Jenkins Jenkins: before 1.424.2 (fixed in 1.424.2); before 1.447 (fixed in 1.447)

Published 2020-02-24. Last modified 2026-06-16.