CVE-2017-1000353
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Jenkins Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-502
מוצרים מושפעים
jenkins: jenkins; oracle: communications cloud native core automated test suite
קישורים
- https://jenkins.io/security/advisory/2017-04-26/ Vendor Advisory
- https://jenkins.io/security/advisory/2017-04-26/ Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.exploit-db.com/exploits/41965/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41965/ ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-C… Permissions RequiredThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/98056 Broken Link
- http://packetstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-C… Permissions RequiredThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/98056 Broken Link