7.5
CWE
770 404
Advisory Published
Advisory Published
Updated

CVE-2023-27901

First published: Wed Mar 08 2023(Updated: )

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.

Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com

Affected SoftwareAffected VersionHow to fix
maven/org.jenkins-ci.main:jenkins-core>=2.376<2.387.1
2.387.1
maven/org.jenkins-ci.main:jenkins-core>=2.388<2.394
2.394
maven/org.jenkins-ci.main:jenkins-core<2.375.4
2.375.4
<2.375.4
<2.394
Jenkins Jenkins<2.375.4
Jenkins Jenkins<2.394
redhat/Jenkins<2.394
2.394
redhat/LTS<2.375.4
2.375.4
redhat/LTS<2.387.1
2.387.1
redhat/jenkins<0:2.387.3.1684911776-3.el8
0:2.387.3.1684911776-3.el8

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is CVE-2023-27901?

    CVE-2023-27901 is a vulnerability in Jenkins that allows attackers to trigger a denial of service (DoS) attack.

  • What is the severity of CVE-2023-27901?

    CVE-2023-27901 has a severity rating of 7.5 (high).

  • How does CVE-2023-27901 affect Jenkins?

    CVE-2023-27901 affects versions of Jenkins up to 2.393 and LTS 2.375.3. It uses the Apache Commons FileUpload library without specifying limits for the number of request parts, allowing attackers to trigger a denial of service.

  • How can I fix CVE-2023-27901?

    You can fix CVE-2023-27901 by updating Jenkins to version 2.394 or LTS to version 2.375.4.

  • Where can I find more information about CVE-2023-27901?

    You can find more information about CVE-2023-27901 on the CVE website, NVD website, Jenkins Security Advisory, and Red Hat Bugzilla.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203