Back

HIGH

jenkins: Jenkins core bundled vulnerable version of the commons-fileupload library (SECURITY-490)

Published Jan 26, 2018

Description

Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 26, 2018
Updated Aug 5, 2024
Reserved Nov 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 11, 2017
GHSA-F7F6-XRWC-9C57