vulnerability

Jenkins Advisory 2018-05-09: CVE-2018-1000193: Users were able to register user names containing control characters

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Jun 5, 2018
Added
Aug 23, 2018
Modified
Aug 11, 2025

Description

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.

Solutions

jenkins-lts-upgrade-2_107_3jenkins-upgrade-2_121
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.