CVE-2017-1000353
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| jenkins | jenkins | * |
| jenkins | jenkins | * |
| oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 |
GitHub Security Advisory GHSA-26wc-3wqp-g3rp
Deserialization of Untrusted Data in Jenkins
References (11)
- http://packetstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-Code-Execution.html Permissions Required, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98056 Broken Link
- https://jenkins.io/security/advisory/2017-04-26/ Vendor Advisory
- https://www.exploit-db.com/exploits/41965/ Exploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpuapr2022.html Patch, Third Party Advisory
- http://packetstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-Code-Execution.html Permissions Required, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98056 Broken Link
- https://jenkins.io/security/advisory/2017-04-26/ Vendor Advisory
- https://www.exploit-db.com/exploits/41965/ Exploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpuapr2022.html Patch, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-1000353 US Government Resource
Risk Scores
Top 0% most likely to be exploited
CISA Known Exploited
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.