Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
The product does not release or incorrectly releases a resource before it is made available for re-use.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Jenkins | Jenkins | * | 2.528.3 (excluding) |
| Jenkins | Jenkins | * | 2.541 (excluding) |
| OpenShift Developer Tools and Services 4.12 | RedHat | ocp-tools-4/jenkins-rhel8:sha256:30b043d6c77a18e0f3ff2e30da493588d9c7b6cc91ff887100ef869853e264f3 | * |
| OpenShift Developer Tools and Services 4.13 | RedHat | ocp-tools-4/jenkins-rhel8:sha256:30b043d6c77a18e0f3ff2e30da493588d9c7b6cc91ff887100ef869853e264f3 | * |
| OpenShift Developer Tools and Services 4.14 | RedHat | ocp-tools-4/jenkins-rhel8:sha256:27db4f7a070211cfe9a0383cf784a664fcbe3a82605611f9f9d8c99cf93c31aa | * |
| OpenShift Developer Tools and Services 4.15 | RedHat | ocp-tools-4/jenkins-rhel8:sha256:27db4f7a070211cfe9a0383cf784a664fcbe3a82605611f9f9d8c99cf93c31aa | * |
| OpenShift Developer Tools and Services 4.16 | RedHat | ocp-tools-4/jenkins-rhel9:sha256:c19b9a5471b0b496011fadb920a099a20b918ec326693e0ae5b2b306d2c7a57b | * |
| OpenShift Developer Tools and Services 4.17 | RedHat | ocp-tools-4/jenkins-rhel9:sha256:c19b9a5471b0b496011fadb920a099a20b918ec326693e0ae5b2b306d2c7a57b | * |
| OpenShift Developer Tools and Services 4.18 | RedHat | ocp-tools-4/jenkins-rhel9:sha256:c19b9a5471b0b496011fadb920a099a20b918ec326693e0ae5b2b306d2c7a57b | * |
| OpenShift Developer Tools and Services 4.19 | RedHat | ocp-tools-4/jenkins-rhel9:sha256:c19b9a5471b0b496011fadb920a099a20b918ec326693e0ae5b2b306d2c7a57b | * |
| OpenShift Developer Tools and Services 4.2 | RedHat | ocp-tools-4/jenkins-rhel9:sha256:c19b9a5471b0b496011fadb920a099a20b918ec326693e0ae5b2b306d2c7a57b | * |