Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27900

Опубликовано: 10 мар. 2023
Источник: redhat
CVSS3: 7.5

Описание

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.

A flaw was found in Jenkins. Affected versions of Jenkins use the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.

Отчет

OpenShift 3.11 is already in the ELS support model phase. The Jenkins components are out of the scope of the ELS support; hence OpenShift 3.11 Jenkins component is marked in this CVE as Out of Support Scope.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkinsOut of support scope
Red Hat OpenShift Container Platform 4jenkinsAffected
OCP-Tools-4.13-RHEL-8jenkinsFixedRHSA-2023:329924.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-404

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.

CVSS3: 7.5
debian
почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Com ...

CVSS3: 6.5
github
почти 3 года назад

Denial of service in Jenkins Core

7.5 High

CVSS3