Description
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
Remediation
References
Related Vulnerabilities
Chamilo Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2026-33702)
WordPress Plugin WP Socializer-Simple & Easy Social Media Share Icons Cross-Site Scripting (2.4.2)
Drupal Improper Control of Dynamically-Managed Code Resources Vulnerability (CVE-2025-31674)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2005-2946)