Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
The product does not release or incorrectly releases a resource before it is made available for re-use.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Jenkins | Jenkins | * | 2.528.3 (excluding) |
| Jenkins | Jenkins | * | 2.541 (excluding) |
| OpenShift Developer Tools and Services 4.12 | RedHat | ocp-tools-4/jenkins-rhel8:v4.12.0-1765819949 | * |
| OpenShift Developer Tools and Services 4.13 | RedHat | ocp-tools-4/jenkins-rhel8:v4.13.0-1765819949 | * |
| OpenShift Developer Tools and Services 4.14 | RedHat | ocp-tools-4/jenkins-rhel8:v4.14.0-1765820005 | * |
| OpenShift Developer Tools and Services 4.15 | RedHat | ocp-tools-4/jenkins-rhel8:v4.15.0-1765820005 | * |
| OpenShift Developer Tools and Services 4.16 | RedHat | ocp-tools-4/jenkins-rhel9:v4.16.0-1765868606 | * |
| OpenShift Developer Tools and Services 4.17 | RedHat | ocp-tools-4/jenkins-rhel9:v4.17.0-1765868606 | * |
| OpenShift Developer Tools and Services 4.18 | RedHat | ocp-tools-4/jenkins-rhel9:v4.18.0-1765868606 | * |
| OpenShift Developer Tools and Services 4.19 | RedHat | ocp-tools-4/jenkins-rhel9:v4.19.0-1765868606 | * |
| OpenShift Developer Tools and Services 4.2 | RedHat | ocp-tools-4/jenkins-rhel9:v4.20.0-1765868606 | * |