Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Feb 9, 2022 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Nov 4, 2022 | Feb 10, 2022 |
| Jenkins 2022 02 09 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.334Upgrade Jenkins LTS to version 2.319.3 | Jul 23, 2026 | Feb 9, 2022 |
| Jenkins 2022 02 09_cve 2021 43859 | — | — | Feb 10, 2022 | Feb 1, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub