CVE-2012-6072

medium
Published 2013-02-24 ยท Modified 2025-03-13
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

Jenkins allows HTTP Injection and Response Splitting

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.jenkins-ci.main:jenkins-core>=1.481,<1.4911.491
java Mavenorg.jenkins-ci.main:jenkins-core<1.480.11.480.1

Application impact

VendorProductVersionsFixed
cloudbeesjenkins1.447.1.1
cloudbeesjenkins1.447.2.2
cloudbeesjenkins1.447.3.1
cloudbeesjenkins1.400
cloudbeesjenkins1.424
cloudbeesjenkins1.447
jenkinsjenkins{"endIncluding":"1.466.2"}
jenkinsjenkins1.409.1
jenkinsjenkins1.409.2
jenkinsjenkins1.409.3
jenkinsjenkins1.424.1
jenkinsjenkins1.424.2
jenkinsjenkins1.424.3
jenkinsjenkins1.424.4
jenkinsjenkins1.424.5
jenkinsjenkins1.424.6
jenkinsjenkins1.447.1
jenkinsjenkins1.447.2
jenkinsjenkins1.466.1
cloudbeesjenkins1.466.1.2
cloudbeesjenkins1.466.2.1
cloudbeesjenkins{"endIncluding":"1.480.3.1"}
jenkinsjenkins1.400
jenkinsjenkins1.401
jenkinsjenkins1.402
jenkinsjenkins1.403
jenkinsjenkins1.404
jenkinsjenkins1.405
jenkinsjenkins1.406
jenkinsjenkins1.407
jenkinsjenkins1.408
jenkinsjenkins1.409
jenkinsjenkins1.410
jenkinsjenkins1.411
jenkinsjenkins1.412
jenkinsjenkins1.413
jenkinsjenkins1.414
jenkinsjenkins1.415
jenkinsjenkins1.416
jenkinsjenkins1.417
jenkinsjenkins1.418
jenkinsjenkins1.419
jenkinsjenkins1.420
jenkinsjenkins1.421
jenkinsjenkins1.422
jenkinsjenkins1.423
jenkinsjenkins1.424
jenkinsjenkins1.425
jenkinsjenkins1.426
jenkinsjenkins1.427
jenkinsjenkins1.428
jenkinsjenkins1.429
jenkinsjenkins1.430
jenkinsjenkins1.431
jenkinsjenkins1.432
jenkinsjenkins1.433
jenkinsjenkins1.434
jenkinsjenkins1.435
jenkinsjenkins1.436
jenkinsjenkins1.437
cloudbeesjenkins1.424.0.2
cloudbeesjenkins1.424.0.4
cloudbeesjenkins1.424.1.1
cloudbeesjenkins1.424.2.1
cloudbeesjenkins1.424.4.1
cloudbeesjenkins1.424.5.1
cloudbeesjenkins1.424.6.1
cloudbeesjenkins1.424.6.11

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.