Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7592-93rm-6gpx

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Injection in Jenkins

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.107.2

2.107.3

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.108, <= 2.120

2.121

EPSS

Процентиль: 73%
0.00759
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 3.7
redhat
больше 7 лет назад

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.

CVSS3: 4.3
nvd
больше 7 лет назад

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.

CVSS3: 4.3
debian
больше 7 лет назад

A improper neutralization of control sequences vulnerability exists in ...

EPSS

Процентиль: 73%
0.00759
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-74