Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qpf-fv36-h4r8

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Infinite Loop in Jenkins Core

A Cron expression form validation could enter infinite loop, potentially resulting in denial of service. The form validation for cron expressions (e.g. "Poll SCM", "Build periodically") could enter infinite loops when cron expressions only matching certain rare dates were entered, blocking request handling threads indefinitely.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.138

2.138

EPSS

Процентиль: 34%
0.00136
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

CVSS3: 4.3
redhat
больше 7 лет назад

A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

CVSS3: 6.5
nvd
больше 7 лет назад

A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

CVSS3: 6.5
debian
больше 7 лет назад

A denial of service vulnerability exists in Jenkins 2.137 and earlier, ...

EPSS

Процентиль: 34%
0.00136
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-835