Jenkins Allocation of Resources Without Limits or Throttling Vulnerability - CVE-2021-21607 - Vulnerability Database

Jenkins Allocation of Resources Without Limits or Throttling Vulnerability - CVE-2021-21607

Medium
Reference: CVE-2021-21607
Title: Jenkins Allocation of Resources Without Limits or Throttling Vulnerability
Overview:

Jenkins 2.274 and earlier LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs allowing attackers to request crafted URLs that use all available memory in Jenkins potentially leading to out of memory errors.