CVE-2012-0785

Description

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.868

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2012-0785 are fixed in Jenkins-Core 1.447Windows
Vulnerabilities CVE-2012-0785 are fixed in Jenkins-Core 1.424.2Windows
Vulnerabilities CVE-2012-0785 are fixed in Jenkins-Core for Linux 1.447Linux
Vulnerabilities CVE-2012-0785 are fixed in Jenkins-Core for Linux 1.424.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234