CVE-2012-6072 PUBLISHED

Reported by redhat · Published February 24, 2013

CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a
Mavenorg.jenkins-ci.main:jenkins-core1.481, 1.481

Timeline

References

Open in Interactive Console →