Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
2020-02-24T17:15:13.590
2024-11-21T01:35:43.290
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cloudbees | jenkins | < 1.400.0.11 | Yes |
Application | cloudbees | jenkins | < 1.424.2.1 | Yes |
Application | jenkins | jenkins | < 1.424.2 | Yes |
Application | jenkins | jenkins | < 1.447 | Yes |