Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cjv-93g7-c6mv

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Loop with Unreachable Exit Condition in Jenkins

A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.138.3

2.138.4

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.140, <= 2.153

2.154

EPSS

Процентиль: 44%
0.00216
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
redhat
около 7 лет назад

A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

CVSS3: 6.5
nvd
около 7 лет назад

A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

CVSS3: 6.5
debian
около 7 лет назад

A denial of service vulnerability exists in Jenkins 2.153 and earlier, ...

EPSS

Процентиль: 44%
0.00216
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-835