A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-12-10T14:00:00

Updated: 2019-03-13T09:57:01

Reserved: 2018-12-10T00:00:00


Link: CVE-2018-1000863

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-12-10T14:29:01.510

Modified: 2019-10-03T00:03:26.223


Link: CVE-2018-1000863

JSON object: View

cve-icon Redhat Information

No data.

CWE