VDB

CVE-2023-27901

CVE-2023-27901 PUBLISHED CVSS 7.5 HIGH

Jenkins LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.

EPSS 0.98% · 60.7th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.98%
60.7th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0
Bitnamijenkins0

Timeline

  • Mar 8, 2023 CVE Published
  • Mar 9, 2023 EPSS Score
  • Mar 11, 2023 PoC Published
  • Apr 17, 2023 EPSS Score
  • May 27, 2023 EPSS Score
  • Jul 5, 2023 EPSS Score
  • Aug 14, 2023 EPSS Score
  • Sep 22, 2023 EPSS Score
  • Nov 1, 2023 EPSS Score
  • Dec 10, 2023 EPSS Score
  • Jan 19, 2024 EPSS Score
  • Feb 27, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›