GHSA-h76p-mc68-jv3p
HIGHCVE-2023-27901Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.
- Affected
- >=0, <2.394.0
- Fixed in
- 2.387.1
- Published
- 2023-03-10
- Source
- github