{"id":"CVE-2012-0785","description":"Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka \"the Hash DoS attack.\"","cvssScore":7.5,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssMetrics":[{"version":"3.1","score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":7.8,"vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-400"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2020-02-24","lastModified":"2026-06-16","affectedProducts":[{"vendor":"cloudbees","product":"jenkins","versionStart":"\u003e=1.400.0","versionEnd":"\u003c1.400.0.11"},{"vendor":"cloudbees","product":"jenkins","versionStart":"\u003e=1.424.0","versionEnd":"\u003c1.424.2.1"},{"vendor":"jenkins","product":"jenkins","versionEnd":"\u003c1.424.2"},{"vendor":"jenkins","product":"jenkins","versionEnd":"\u003c1.447"}],"totalAffectedProducts":2,"references":[{"url":"https://access.redhat.com/security/cve/cve-2012-0785","source":"patch-hint","tags":["redhat-cve"]},{"url":"https://jenkins.io/security/advisory/2012-01-12","source":"osv","tags":["WEB"]},{"url":"https://security-tracker.debian.org/tracker/CVE-2012-0785","source":"osv","tags":["WEB"]},{"url":"https://www.cloudbees.com/jenkins-security-advisory-2012-01-12","source":"osv","tags":["WEB"]},{"url":"http://www.openwall.com/lists/oss-security/2012/01/20/8","source":"osv","tags":["WEB"]},{"url":"https://jenkins.io/security/advisory/2012-01-12/","source":"secalert@redhat.com","tags":["Vendor Advisory"]}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.jenkins-ci.main:jenkins-core"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (redhat-cve tier): https://access.redhat.com/security/cve/cve-2012-0785"},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"patchHintUrl":"https://access.redhat.com/security/cve/cve-2012-0785","patchHintTier":"redhat-cve","affectedProducts":[{"vendor":"cloudbees","product":"jenkins","isKnown":false,"cpe":"cpe:2.3:a:cloudbees:jenkins:*:*:*:*:enterprise:*:*:*"},{"vendor":"jenkins","product":"jenkins","isKnown":false,"cpe":"cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*"}],"affectedPackages":[{"name":"org.jenkins-ci.main:jenkins-core","introduced":"1.425","fixed":"1.447"},{"name":"org.jenkins-ci.main:jenkins-core","introduced":"0","fixed":"1.424.2"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.03351,"percentile":0.88003},"ssvc":{"available":false},"patchHintUrl":"https://access.redhat.com/security/cve/cve-2012-0785","patchHintTier":"redhat-cve"}