CVE-2018-1000193: Injection Vulnerability
(updated )
An improper neutralization of control sequences vulnerability exists in Jenkins in HudsonPrivateSecurityRealm.java
that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.
References
Detect and mitigate CVE-2018-1000193 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →