CVE-2022-0538: High severity jenkins lts vulnerability
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
Other sources
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier is affected by the XStream library’s vulnerability CVE-2021-43859. This library is used by Jenkins to serialize and deserialize various XML files, like global and job config.xml, build.xml, and numerous others.
This allows attackers able to submit crafted XML files to Jenkins to be parsed as configuration, e.g. through the POST config.xml API, to cause a denial of service (DoS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0538?
The severity of CVE-2022-0538 is high with a CVSS score of 7.5.
How does CVE-2022-0538 impact Jenkins?
CVE-2022-0538 can allow unconstrained resource usage and affects Jenkins versions 2.333 and earlier, as well as LTS 2.319.2 and earlier.
Which software versions are affected by CVE-2022-0538?
CVE-2022-0538 affects Jenkins versions 2.333 and earlier, as well as LTS 2.319.2 and earlier.
Are there any fixes available for CVE-2022-0538?
Yes, the fix for CVE-2022-0538 is not yet available. It is recommended to closely monitor the Jenkins security advisory for updates.
Where can I find more information about CVE-2022-0538?
You can find more information about CVE-2022-0538 in the Jenkins security advisory: https://www.jenkins.io/security/advisory/2022-02-09/#SECURITY-2602