Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3663 Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.
Github GHSA Github GHSA GHSA-cxqw-vjcr-gp5g Excessive memory allocation in graph URLs leads to denial of service in Jenkins
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-03T18:16:23.786Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2021-21607

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-13T16:15:13.740

Modified: 2024-11-21T05:48:41.373

Link: CVE-2021-21607

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-01-13T00:00:00Z

Links: CVE-2021-21607 - Bugzilla

cve-icon OpenCVE Enrichment

No data.