VDB
CVE-2023-27901
CVE-2023-27901
PUBLISHED
CVSS 7.5 HIGH
Jenkins LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.
EPSS 0.98% · 60.7th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.98%
60.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | jenkins | 0 |
| Bitnami | jenkins | 0 |
Timeline
- Mar 8, 2023 CVE Published
- Mar 9, 2023 EPSS Score
- Mar 11, 2023 PoC Published
- Apr 17, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 5, 2023 EPSS Score
- Aug 14, 2023 EPSS Score
- Sep 22, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
- Dec 10, 2023 EPSS Score
- Jan 19, 2024 EPSS Score
- Feb 27, 2024 EPSS Score