CVE-2017-1000394: Input Validation
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000394?
CVE-2017-1000394 has a severity rating of medium due to the denial-of-service vulnerability it poses.
How do I fix CVE-2017-1000394?
To fix CVE-2017-1000394, upgrade to Jenkins version 2.73.2 or later, or 2.83.1 or later.
What versions of Jenkins are affected by CVE-2017-1000394?
CVE-2017-1000394 affects Jenkins 2.73.1 and earlier, as well as 2.83 and earlier.
Does CVE-2017-1000394 involve any third-party libraries?
Yes, CVE-2017-1000394 involves a vulnerability in the bundled version of the commons-fileupload library.
What is the nature of the vulnerability in CVE-2017-1000394?
CVE-2017-1000394 is a denial-of-service vulnerability that affects the commons-fileupload library included with certain Jenkins versions.