Description
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.
Remediation
References
Related Vulnerabilities
ownCloud CVE-2017-9339 Vulnerability (CVE-2017-9339)
WordPress Plugin The Crawl Rate Tracker 'sbtracking-chart-data.php' SQL Injection (2.0.2)
WordPress Plugin RSS Post Importer Unspecified Vulnerability (2.5.0)
WordPress Plugin Spicy Blogroll Local File Include (1.0.0)
WordPress Plugin CWIS-Antivirus Security Scanner Unspecified Vulnerability (2.3.2)