HIGH
jenkins: Jenkins core bundled vulnerable version of the commons-fileupload library (SECURITY-490)
Published Jan 26, 2018
7.5
HIGHCVSS 3.0
EPSS 1.15%
Description
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
Affected products
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2017-1000394 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1501813 Issue Tracking
- https://github.com/advisories/GHSA-f7f6-xrwc-9c57 Advisory
- https://github.com/jenkinsci/jenkins/commit/ea981a029cb985b71f3a0dc0f9ce3b3e3e6c001b
- https://jenkins.io/security/advisory/2017-10-11/ x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000394
- https://www.cve.org/CVERecord?id=CVE-2017-1000394
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2017-1000394 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1501813 | Issue Tracking | |
| https://github.com/advisories/GHSA-f7f6-xrwc-9c57 | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/ea981a029cb985b71f3a0dc0f9ce3b3e3e6c001b | ||
| https://jenkins.io/security/advisory/2017-10-11/ | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000394 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000394 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 26, 2018
Updated Aug 5, 2024
Reserved Nov 29, 2017
Link CVE-2017-1000394
CISA Vulnrichment
GHSA-F7F6-XRWC-9C57 Updated n/a