logo

CVE-2012-0785 org.jenkins-ci.main:jenkins-core

Package

Manager: maven
Name: org.jenkins-ci.main:jenkins-core
Vulnerable Version: >=1.425 <1.447 || >=0 <1.424.2

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.01939 pctl0.82707

Details

Hash collision attack vulnerability in Jenkins Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

Metadata

Created: 2022-04-23T00:40:48Z
Modified: 2024-01-30T21:09:35Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-pchp-c5w8-47gc/GHSA-pchp-c5w8-47gc.json
CWE IDs: []
Alternative ID: GHSA-pchp-c5w8-47gc
Finding: F067
Auto approve: 1