Back

MEDIUM

jenkins: Cron expression form validation could enter infinite loop, potentially resulting in denial of service

Published Aug 23, 2018

Description

A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

Affected products

Remediation

Red Hat statement

Users of OpenShift Container Platform 3.x should upgrade to 3.11 to pick up a fix for this issue.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 23, 2018
Updated Sep 17, 2024
Reserved Aug 23, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 15, 2018
GHSA-8QPF-FV36-H4R8