CVE-2014-3661Uncontrolled Resource Consumption in Jenkins

Severity
5.0MEDIUMNVD
EPSS
0.2%
top 63.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16
Latest updateMay 17

Description

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDjenkins/jenkins1.582+1

🔴Vulnerability Details

3
GHSA
Jenkins Denial of Service vulnerability2022-05-17
OSV
Jenkins Denial of Service vulnerability2022-05-17
CVEList
CVE-2014-3661: Jenkins before 12014-10-16

📋Vendor Advisories

2
Red Hat
jenkins: denial of service (SECURITY-87)2014-10-02
Jenkins
Jenkins Security Advisory 2014-10-012014-10-01

💬Community

1
Bugzilla
CVE-2014-3661 jenkins: denial of service (SECURITY-87)2014-09-30
CVE-2014-3661 — Uncontrolled Resource Consumption | cvebase