Description
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing default admin user in the process and allowing a wide variety of impacts.
Remediation
References
Related Vulnerabilities
OpenSSL Other Vulnerability (CVE-2015-0289)
WordPress Plugin Events Calendar for Google Local File Inclusion (2.1.0)
WordPress Plugin WordPress PDF Light Viewer Command Injection (1.4.11)
Joomla! Core 2.5.x Information Disclosure (2.5.0 - 2.5.3)
Oracle Database Server CVE-2023-22073 Vulnerability (CVE-2023-22073)