Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-34wx-x2w9-vqm3

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

DoS vulnerability in bundled XStream library in Jenkins Core

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier is affected by the XStream library’s vulnerability CVE-2021-43859. This library is used by Jenkins to serialize and deserialize various XML files, like global and job config.xml, build.xml, and numerous others.

This allows attackers able to submit crafted XML files to Jenkins to be parsed as configuration, e.g. through the POST config.xml API, to cause a denial of service (DoS).

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.320, < 2.334

2.334

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.319.3

2.319.3

EPSS

Процентиль: 71%
0.00675
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
redhat
почти 4 года назад

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

CVSS3: 7.5
nvd
почти 4 года назад

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

CVSS3: 7.5
debian
почти 4 года назад

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStr ...

EPSS

Процентиль: 71%
0.00675
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-502