vulnerability

Jenkins Advisory 2022-02-09: CVE-2021-43859: CVE-2022-0538: DoS vulnerability in bundled XStream library

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Feb 9, 2022
Added
Jul 12, 2022
Modified
Aug 11, 2025

Description

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

Solutions

jenkins-lts-upgrade-2_319_3jenkins-upgrade-2_334
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.