Lucene search

K
githubGitHub Advisory DatabaseGHSA-H76P-MC68-JV3P
HistoryMar 10, 2023 - 9:30 p.m.

Denial of service in Jenkins Core

2023-03-1021:30:19
CWE-770
GitHub Advisory Database
github.com
25
jenkins
cve-2023-24998
apache commons fileupload
requestimpl

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.026

Percentile

90.5%

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.

Affected configurations

Vulners
Node
org.jenkins-ci.mainjenkins-coreRange2.3762.387.1
OR
org.jenkins-ci.mainjenkins-coreRange2.3882.394
OR
org.jenkins-ci.mainjenkins-coreRange<2.375.4
VendorProductVersionCPE
org.jenkins-ci.mainjenkins-core*cpe:2.3:a:org.jenkins-ci.main:jenkins-core:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.026

Percentile

90.5%