-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.main:jenkins-core | maven | >= 1.566, < 1.583 | 1.583 |
| org.jenkins-ci.main:jenkins-core | maven | < 1.565.3 | 1.565.3 |
The vulnerability (CVE-2014-3662/SECURITY-110) explicitly involves user enumeration via login response discrepancies. Jenkins' HudsonPrivateSecurityRealm is the primary class handling local user authentication. The doLogin method would be responsible for validating credentials, and pre-patch versions of this function likely leaked username existence through error message differentiation. The security advisory and CVE description align with this authentication flow vulnerability.
Ongoing coverage of React2Shell