QID 730064
Date Published: 2021-04-29
QID 730064: Jenkins Core Denial Of Service Vulnerability(Jenkins Security Advisory 2021-04-20)
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
Affected Versions:
Jenkins weekly up to and including 2.285
Jenkins LTS up to and including 2.277.2
Fixed Versions:
Jenkins weekly should be updated to version 2.286
Jenkins LTS should be updated to version 2.277.3
QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version by sending a crafted GET request to Jenkins. This QID also detects the vulnerable version from login page or HTTP header.
This vulnerability may allow unauthenticated attackers to cause a denial of service if Winstone-Jetty is configured to handle SSL/TLS connections.
For further details refer to Jenkins Security Advisory 2021-04-20
- Jenkins Security Advisory 2021-04-20 -
www.jenkins.io/security/advisory/2021-04-20/
CVEs related to QID 730064
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Jenkins Security Advisory 2021-04-20 |
|