Description
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
Remediation
References
Related Vulnerabilities
Oracle Database Server Other Vulnerability (CVE-2006-0551)
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-35030)
Microsoft SQL Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2003-0230)
Liferay DXP Use of Web Browser Cache Containing Sensitive Information Vulnerability (CVE-2025-62276)