Back

CVE-2017-1000353

CRITICAL CISA KEV

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.

Published: Jan 29, 2018 Modified: Jun 17, 2026
CWE-502 CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
jenkins jenkins *
jenkins jenkins *
oracle communications_cloud_native_core_automated_test_suite 1.9.0

GitHub Security Advisory GHSA-26wc-3wqp-g3rp

Deserialization of Untrusted Data in Jenkins

maven org.jenkins-ci.main:jenkins-core >= 2.50, <= 2.56 Fixed: 2.57
maven org.jenkins-ci.main:jenkins-core <= 2.46.1 Fixed: 2.46.2

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 99.68%

Top 0% most likely to be exploited

Threat Score 99.1 / 100

CISA Known Exploited

Date Added: 2025-10-02
Due Date: 2025-10-23
Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Data Sources

NVD CISA KEV EPSS GitHub