CVE-2018-1000864: Jenkins

Medium severity, CVSS 6.5. EPSS: 2.8% chance of exploitation in the next 30 days.

A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

Affected products

  • Jenkins Jenkins: up to and including 2.138.3; up to and including 2.153
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2018-12-10. Last modified 2026-06-17.