CVE-2021-21607Allocation of Resources Without Limits or Throttling in Project Jenkins

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 43.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 24

Description

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDjenkins/jenkins2.263.1+1
CVEListV5jenkins_project/jenkinsunspecified2.274+1

🔴Vulnerability Details

3
OSV
Excessive memory allocation in graph URLs leads to denial of service in Jenkins2022-05-24
GHSA
Excessive memory allocation in graph URLs leads to denial of service in Jenkins2022-05-24
CVEList
CVE-2021-21607: Jenkins 22021-01-13

📋Vendor Advisories

2
Red Hat
jenkins: Excessive memory allocation in graph URLs leads to denial of service2021-01-13
Jenkins
Jenkins Security Advisory 2021-01-132021-01-13
CVE-2021-21607 — Jenkins Project Jenkins vulnerability | cvebase