CVE-2017-1000394

Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
References
Link Resource
https://jenkins.io/security/advisory/2017-10-11/ Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2018-01-26 02:29

Updated : 2024-02-04 19:46


NVD link : CVE-2017-1000394

Mitre link : CVE-2017-1000394

CVE.ORG link : CVE-2017-1000394


JSON object : View

Products Affected

jenkins

  • jenkins
CWE
CWE-20

Improper Input Validation