PoC Index

CVE-2018-1000863

HIGH 8.2EPSS 6.8%

A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.

CVSS v3.0
8.2 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CVSS v3.0
8.2 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CVSS v2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
6.76% chance of exploitation in the next 30 days, 94th percentile
Published
2018-12-10
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related