Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0538

Опубликовано: 09 фев. 2022
Источник: redhat
CVSS3: 7.5

Описание

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

A denial of service (DoS) flaw was found in Jenkins. This flaw allows an attacker to define custom XStream converters that do not protect against the vulnerability in CVE-2021-43859, allowing for uncontrolled resource consumption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jenkinsNot affected
Red Hat OpenShift Container Platform 3.11jenkinsNot affected
Red Hat OpenShift Container Platform 4jenkinsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2052679jenkins: DoS vulnerability in bundled XStream library

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

CVSS3: 7.5
debian
почти 4 года назад

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStr ...

CVSS3: 6.5
github
почти 4 года назад

DoS vulnerability in bundled XStream library in Jenkins Core

7.5 High

CVSS3