CVE-2018-1999044
Infinite Loop in Jenkins Core
6.5
MEDIUM
CVSS 3.1
EPSS 1.2%
描述
A Cron expression form validation could enter infinite loop, potentially resulting in denial of service. The form validation for cron expressions (e.g. "Poll SCM", "Build periodically") could enter infinite loops when cron expressions only matching certain rare dates were entered, blocking request handling threads indefinitely.
如何修補 CVE-2018-1999044
要修補 CVE-2018-1999044,請將受影響套件升級到下列已修補版本。
- —升級至 2.138 或更新版本
CVE-2018-1999044 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.138
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |