VDB
Sign up
HIGH7.5

GHSA-9p56-p6mw-w8qc

Jenkins has a Denial of service vulnerability in HTTP-based CLI

Quick fix

GHSA-9p56-p6mw-w8qc — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.541</version> for org.jenkins-ci.main:jenkins-core

Details

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jenkins-ci.main:jenkins-core
Introduced in: 2.529Fixed in: 2.541
Fix# pom.xml: bump <version>2.541</version> for org.jenkins-ci.main:jenkins-core
Maven/org.jenkins-ci.main:cli
Introduced in: 2.529Fixed in: 2.541
Fix# pom.xml: bump <version>2.541</version> for org.jenkins-ci.main:cli
Maven/org.jenkins-ci.main:jenkins-core
Introduced in: 0Fixed in: 2.528.3
Fix# pom.xml: bump <version>2.528.3</version> for org.jenkins-ci.main:jenkins-core
Maven/org.jenkins-ci.main:cli
Introduced in: 0Fixed in: 2.528.3
Fix# pom.xml: bump <version>2.528.3</version> for org.jenkins-ci.main:cli

References