Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pchp-c5w8-47gc

Опубликовано: 23 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Hash collision attack vulnerability in Jenkins

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.425, < 1.447

1.447

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.424.2

1.424.2

EPSS

Процентиль: 83%
0.01868
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

CVSS3: 7.5
nvd
почти 6 лет назад

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

CVSS3: 7.5
debian
почти 6 лет назад

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins L ...

EPSS

Процентиль: 83%
0.01868
Низкий

7.5 High

CVSS3