Business information leak In org.jenkins-ci.main:jenkins-core
Description
Jenkins Exposure of Sensitive Information to an Unauthorized Actor vulnerability Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 1.583, 1.565.3 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.