First published: Wed Feb 09 2022(Updated: )
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <2.319.3 | |
Jenkins Jenkins | <2.334 | |
maven/org.jenkins-ci.main:jenkins-core | <2.319.3 | 2.319.3 |
maven/org.jenkins-ci.main:jenkins-core | >=2.320<2.334 | 2.334 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-0538 is high with a CVSS score of 7.5.
CVE-2022-0538 can allow unconstrained resource usage and affects Jenkins versions 2.333 and earlier, as well as LTS 2.319.2 and earlier.
CVE-2022-0538 affects Jenkins versions 2.333 and earlier, as well as LTS 2.319.2 and earlier.
Yes, the fix for CVE-2022-0538 is not yet available. It is recommended to closely monitor the Jenkins security advisory for updates.
You can find more information about CVE-2022-0538 in the Jenkins security advisory: https://www.jenkins.io/security/advisory/2022-02-09/#SECURITY-2602