Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000193

Опубликовано: 09 мая 2018
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3jenkinsAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1576708jenkins: Users were able to register user names containing control characters (SECURITY-786)

EPSS

Процентиль: 62%
0.01045
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 8 лет назад

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.

CVSS3: 4.3
debian
около 8 лет назад

A improper neutralization of control sequences vulnerability exists in ...

CVSS3: 4.3
github
больше 4 лет назад

Injection in Jenkins

EPSS

Процентиль: 62%
0.01045
Низкий

3.7 Low

CVSS3