Description
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.
Remediation
References
Related Vulnerabilities
Zenphoto Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-0993)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-1854)
MySQL Use After Free Vulnerability (CVE-2019-7317)
WordPress Plugin Custom Fields Search by BestWebSoft Cross-Site Scripting (1.3.1)
WordPress Plugin YITH WooCommerce Zoom Magnifier Cross-Site Scripting (1.2.6)