Aller au contenu

Fiche vulnérabilité

CVE-2022-0538 : faille élevée Jenkins project Jenkins (CVSS 7.5)

Description

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
9 févr. 2022
Dernière mise à jour
2 août 2024

Produits concernés

  • Jenkins project Jenkins

Références

Rechercher une autre vulnérabilité dans la base CVE