cve/2022/CVE-2022-0538.md

19 lines
730 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-0538](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0538)
![](https://img.shields.io/static/v1?label=Product&message=Jenkins&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=unspecified%3C%3D%202.333%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/r00t4dm/r00t4dm