CVE-2018-1000408: Jenkins

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.

Affected products

  • Jenkins Jenkins: up to and including 2.138.1; up to and including 2.145

Published 2019-01-09. Last modified 2026-06-17.