CVE-2023-27900

HIGH

Jenkins < 2.375.4, < 2.394 - Denial of Service via Unlimited Request Parts in MultipartFormDataParser

Title source: llm
STIX 2.1

Description

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0062
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (3)
jenkins/jenkins < 2.375.4
jenkins/jenkins < 2.394
org.jenkins-ci.main/jenkins-core 2.388 - 2.394Maven
Published Mar 10, 2023
Tracked Since Feb 18, 2026