Fiche vulnérabilité
CVE-2022-0538 : faille élevée Jenkins project Jenkins (CVSS 7.5)
Description
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 9 févr. 2022
- Dernière mise à jour
- 2 août 2024
Produits concernés
- Jenkins project Jenkins