Description
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.
Remediation
References
Related Vulnerabilities
WordPress Plugin BJ Lazy Load Remote Code Execution (0.7.5)
WordPress Plugin Import and export users and customers Multiple Vulnerabilities (1.9.4.6)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3181)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-1686)