VDB

CVE-2023-27900

CVE-2023-27900 PUBLISHED CVSS 7.5 HIGH

Jenkins LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.

EPSS 0.98% · 60.8th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.98%
60.8th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0
Bitnamijenkins0

Timeline

  • Mar 8, 2023 CVE Published
  • Mar 9, 2023 EPSS Score
  • Mar 16, 2023 CVE Updated
  • Apr 17, 2023 EPSS Score
  • May 27, 2023 EPSS Score
  • Jul 5, 2023 EPSS Score
  • Aug 14, 2023 EPSS Score
  • Sep 22, 2023 EPSS Score
  • Nov 1, 2023 EPSS Score
  • Dec 10, 2023 EPSS Score
  • Feb 27, 2024 EPSS Score
  • Apr 7, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›