A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-12-10T14:00:00

Updated: 2024-08-05T12:47:57.309Z

Reserved: 2018-12-10T00:00:00

Link: CVE-2018-1000863

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-12-10T14:29:01.510

Modified: 2019-10-03T00:03:26.223

Link: CVE-2018-1000863

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-12-05T00:00:00Z

Links: CVE-2018-1000863 - Bugzilla