Описание
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.56 (включая)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
Конфигурация 2Версия до 2.46.1 (включая)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
EPSS
Процентиль: 62%
0.00429
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 6.5
ubuntu
около 8 лет назад
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.
CVSS3: 5.9
redhat
почти 9 лет назад
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.
CVSS3: 6.5
debian
около 8 лет назад
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier ar ...
EPSS
Процентиль: 62%
0.00429
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-502