Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3663 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors. |
Github GHSA |
GHSA-cxqw-vjcr-gp5g | Excessive memory allocation in graph URLs leads to denial of service in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:16:23.786Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21607
No data.
Status : Modified
Published: 2021-01-13T16:15:13.740
Modified: 2024-11-21T05:48:41.373
Link: CVE-2021-21607
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA