Looking for the vulnerability index of Invicti's legacy products?
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2022-0538) - Vulnerability Database

Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2022-0538)

Description

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

References

Related Vulnerabilities