Description
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2009-0994 Vulnerability (CVE-2009-0994)
WordPress Plugin Insert or Embed Articulate Content into WordPress Directory Traversal (4.2999)
MySQL CVE-2014-2434 Vulnerability (CVE-2014-2434)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20415)
phpMyAdmin Resource Management Errors Vulnerability (CVE-2016-5706)