First published: Fri Jan 26 2018(Updated: )
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <=2.73.1 | |
Jenkins Jenkins | <=2.83 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000394 has a severity rating of medium due to the denial-of-service vulnerability it poses.
To fix CVE-2017-1000394, upgrade to Jenkins version 2.73.2 or later, or 2.83.1 or later.
CVE-2017-1000394 affects Jenkins 2.73.1 and earlier, as well as 2.83 and earlier.
Yes, CVE-2017-1000394 involves a vulnerability in the bundled version of the commons-fileupload library.
CVE-2017-1000394 is a denial-of-service vulnerability that affects the commons-fileupload library included with certain Jenkins versions.