jenkins-core is vulnerable to Improper Handling of Case Sensitivity
78
High Risk
User and group name handling mixes lowercase canonical IDs with String#equalsIgnoreCase comparisons that treat some Unicode characters as equal when lowercasing does not. An attacker who can create users or groups with names that match this way can impersonate other users or inherit their permissions when the security realm allows those characters. The fix compares names by canonical form only.
You are affected if you are using a version that falls within the vulnerable range and use a security realm that allows creating users or groups whose names case-insensitively match existing ones with non-ASCII characters.
jenkins-core is vulnerable to Improper Handling of Case Sensitivity in versions 0.0.1 - 2.568.1 and 2.569 - 2.575.
Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant