Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r5x3-2446-hrp7

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Race Condition in Jenkins

A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failure to initialize the setup wizard on the first startup. This resulted in multiple security-related settings not being set to their usual strict default.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.81, <= 2.89.1

2.89.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.90, <= 2.94

2.95

EPSS

Процентиль: 86%
0.02745
Низкий

8.1 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.8
redhat
около 8 лет назад

A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failure to initialize the setup wizard on the first startup. This resulted in multiple security-related settings not being set to their usual strict default.

CVSS3: 8.1
nvd
около 8 лет назад

A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failure to initialize the setup wizard on the first startup. This resulted in multiple security-related settings not being set to their usual strict default.

CVSS3: 8.1
debian
около 8 лет назад

A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 ...

EPSS

Процентиль: 86%
0.02745
Низкий

8.1 High

CVSS3

Дефекты

CWE-362