Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-0538
HistoryFeb 09, 2022 - 1:30 p.m.

CVE-2022-0538

2022-02-0913:30:15
jenkins
www.cve.org
14
jenkins
lts
xstream
converters
vulnerability

AI Score

7.8

Confidence

High

EPSS

0.015

Percentile

87.1%

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

CNA Affected

[
  {
    "product": "Jenkins",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "2.333",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "LTS 2.319.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]