Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27901

Опубликовано: 10 мар. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.

A flaw was found in Jenkins. Affected versions of Jenkins use the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.

Отчет

OpenShift 3.11 is already in the ELS support model phase. The Jenkins components are out of the scope of the ELS support; hence OpenShift 3.11 Jenkins component is marked in this CVE as Out of Support Scope.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkinsOut of support scope
Red Hat OpenShift Container Platform 4jenkinsAffected
OCP-Tools-4.13-RHEL-8jenkinsFixedRHSA-2023:329924.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-404

EPSS

Процентиль: 60%
0.00395
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.

CVSS3: 7.5
debian
почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Com ...

CVSS3: 7.5
github
почти 3 года назад

Denial of service in Jenkins Core

EPSS

Процентиль: 60%
0.00395
Низкий

7.5 High

CVSS3