CVE-2017-1000394: Jenkins
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
Affected products
- Jenkins Jenkins: up to and including 2.73.1; up to and including 2.83
Published 2018-01-26. Last modified 2026-06-17.