PT-2022-13249 · Jenkins · Jenkins

Published

2022-02-09

·

Updated

2024-03-06

·

CVE-2022-0538

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.333 and earlier Jenkins LTS versions 2.319.2 and earlier
Description The issue is related to custom XStream converters that have not been updated to apply protections, allowing unconstrained resource usage.
Recommendations For Jenkins versions 2.333 and earlier, update to a version that applies the necessary protections. For Jenkins LTS versions 2.319.2 and earlier, update to a version that applies the necessary protections. As a temporary workaround, consider restricting the use of custom XStream converters until a patch is available.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2022-0538
CVE-2022-0538
GHSA-34WX-X2W9-VQM3

Affected Products

Jenkins