CVE-2014-2064
Jenkins <1.551, <1.532.2 - Info Disclosure
Title source: llmDescription
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.
Exploits (1)
Scores
EPSS
0.0039
EPSS Percentile
60.0%
Details
CWE
CWE-200
Status
published
Products (3)
jenkins/jenkins
< 1.532.1
jenkins/jenkins
< 1.550
org.jenkins-ci.main/jenkins-core
1.533 - 1.551Maven
Published
Oct 17, 2014
Tracked Since
Feb 18, 2026