Resource exhaustion in Jenkins and Jenkins LTS - CVE-2022-0538
Published: February 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote authenticated attacker can use specially crafted XML files, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Jenkins LTS
How to mitigate CVE-2022-0538
Jenkins LTS - update to 2.319.3