NVD

Id
24046  
Name
CVE-2015-1810  
Description
The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins" own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.  
Reject
 
CVSS Version
2  
CVSS Score
4.6  
Severity
Medium  
CVSS Base Score
4.6  
CVSS Impact Subscore
6.4  
CVSS Exploit Subscore
3.9  
CVSS Vector
(AV:N/AC:H/Au:S/C:P/I:P/A:P)  
Pub Date
2017-01-19  
Published
2015-10-16  
Modified Date
2016-06-15  
Seq
2015-1810  

Actions