vulnerability
Jenkins Advisory 2022-02-09: CVE-2021-43859: CVE-2022-0538: DoS vulnerability in bundled XStream library
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Feb 9, 2022 | Jul 12, 2022 | Aug 11, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Feb 9, 2022
Added
Jul 12, 2022
Modified
Aug 11, 2025
Description
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
Solutions
jenkins-lts-upgrade-2_319_3jenkins-upgrade-2_334
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.