CyberRota Analysis
AI-GeneratedJenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, have a vulnerability in the handling of case-insensitivity for user and group names. This inconsistency allows attackers to create new users or groups that can impersonate existing users, potentially gaining unauthorized access to their permissions. Organizations using these affected versions should prioritize remediation to prevent potential impersonation and privilege escalation attacks.
Original NVD Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.