Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-67635

Опубликовано: 10 дек. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

Jenkins does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-459
https://bugzilla.redhat.com/show_bug.cgi?id=2420998org.jenkins-ci.main/jenkins-core: Jenkins HTTP connection mis-handling

EPSS

Процентиль: 30%
0.00115
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

CVSS3: 7.5
github
4 месяца назад

Jenkins has a Denial of service vulnerability in HTTP-based CLI

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость сервера автоматизации Jenkins, связанная с некорректной зачисткой или освобождением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
redos
3 месяца назад

Уязвимость jenkins

EPSS

Процентиль: 30%
0.00115
Низкий

5.3 Medium

CVSS3