High severity7.5NVD Advisory· Published Jan 26, 2018· Updated Jun 17, 2026
CVE-2017-1000394
CVE-2017-1000394
Description
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.73.2 | 2.73.2 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.74, < 2.84 | 2.84 |
Affected products
3cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*range: <=2.83
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <=2.73.1
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.