Description
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
Remediation
References
http://www.securityfocus.com/bid/106176
https://access.redhat.com/errata/RHBA-2019:0024
https://jenkins.io/security/advisory/2018-12-05/#SECURITY-1072
https://www.tenable.com/security/research/tra-2018-43
Related Vulnerabilities
CVE-2020-17510 Vulnerability in maven package org.apache.shiro:shiro-spring-boot-web-starter
CVE-2019-10389 Vulnerability in maven package org.jenkins-ci.plugins:relution-publisher
CVE-2017-11555 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2014-3579 Vulnerability in maven package org.apache.activemq:apollo-selector
CVE-2019-18394 Vulnerability in maven package org.igniterealtime.openfire:xmppserver