CVE-2013-0331: Input Validation
Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to cause a denial of service via a crafted payload.
Other sources
Jenkins Security Advisory 2013-02-16
A vulnerability allows a malicious user of Jenkins to mount a denial of service attack by feeding a carefully crafted payload to Jenkins.
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0331?
CVE-2013-0331 has been rated as a medium severity vulnerability.
How do I fix CVE-2013-0331?
To fix CVE-2013-0331, upgrade Jenkins to version 1.502 or later.
Who is affected by CVE-2013-0331?
CVE-2013-0331 affects Jenkins versions prior to 1.502 and LTS versions prior to 1.480.3.
What type of attack does CVE-2013-0331 enable?
CVE-2013-0331 enables a denial of service attack by allowing crafted payloads to be used against Jenkins.
Can I exploit CVE-2013-0331 remotely?
Yes, CVE-2013-0331 can be exploited by remote authenticated users with write access.