Описание
Jenkins has a Denial of service vulnerability in HTTP-based CLI
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
Пакеты
org.jenkins-ci.main:jenkins-core
>= 2.529, < 2.541
2.541
org.jenkins-ci.main:cli
>= 2.529, < 2.541
2.541
org.jenkins-ci.main:jenkins-core
< 2.528.3
2.528.3
org.jenkins-ci.main:cli
< 2.528.3
2.528.3
Связанные уязвимости
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
Уязвимость сервера автоматизации Jenkins, связанная с некорректной зачисткой или освобождением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании