Lucene search

K
osvGoogleOSV:GHSA-34WX-X2W9-VQM3
HistoryFeb 10, 2022 - 12:00 a.m.

DoS vulnerability in bundled XStream library in Jenkins Core

2022-02-1000:00:30
Google
osv.dev
20
jenkins
xstream library
vulnerability
cve-2021-43859
xml
denial of service

EPSS

0.015

Percentile

87.1%

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier is affected by the XStream library’s vulnerability CVE-2021-43859. This library is used by Jenkins to serialize and deserialize various XML files, like global and job config.xml, build.xml, and numerous others.

This allows attackers able to submit crafted XML files to Jenkins to be parsed as configuration, e.g. through the POST config.xml API, to cause a denial of service (DoS).