CVE-2023-27901: High severity jenkins lts vulnerability
A flaw was found in Jenkins. Affected versions of Jenkins use the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.
Other sources
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier use the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.
https://www.jenkins.io/security/advisory/2023-03-08/#SECURITY-3030
— Red Hat
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27901?
CVE-2023-27901 is a vulnerability in Jenkins that allows attackers to trigger a denial of service (DoS) attack.
What is the severity of CVE-2023-27901?
CVE-2023-27901 has a severity rating of 7.5 (high).
How does CVE-2023-27901 affect Jenkins?
CVE-2023-27901 affects versions of Jenkins up to 2.393 and LTS 2.375.3. It uses the Apache Commons FileUpload library without specifying limits for the number of request parts, allowing attackers to trigger a denial of service.
How can I fix CVE-2023-27901?
You can fix CVE-2023-27901 by updating Jenkins to version 2.394 or LTS to version 2.375.4.
Where can I find more information about CVE-2023-27901?
You can find more information about CVE-2023-27901 on the CVE website, NVD website, Jenkins Security Advisory, and Red Hat Bugzilla.