CVE-2018-1000863 Information
Feb 14, 2021
cve
Description
A data modification vulnerability exists in Jenkins 2.153 and earlier LTS 2.138.3 and earlier in User.java IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats potentially preventing the victim from logging into Jenkins.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Reference
http://www.securityfocus.com/bid/106176 https://access.redhat.com/errata/RHBA-2019:0024 https://jenkins.io/security/advisory/2018-12-05/SECURITY-1072 https://www.tenable.com/security/research/tra-2018-43
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
HIGH
Base Severity
8.2
Share on: