Red Hat Bugzilla – Bug 1620342
CVE-2018-1999043 jenkins: Ephemeral user record was created on some invalid authentication attempts
Last modified: 2018-10-30 01:31:39 EDT
Jenkins before LTS version 2.121.3 and weekly version 2.138 have a vulnerability exploitable by unauthenticated users. When attempting to authenticate using API token, an ephemeral user record was created to validate the token in case an external security realm was used, and the user record in Jenkins not previously saved, as (legacy) API tokens could exist without a persisted user record. This behavior could be abused to create a large number of ephemeral user records in memory. External Reference: https://jenkins.io/security/advisory/2018-08-15/#SECURITY-672
Created jenkins tracking bugs for this issue: Affects: fedora-all [bug 1620343]