Back

CVE-2018-1000861

CRITICAL CISA KEV

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

Published: Dec 10, 2018 Modified: Jun 17, 2026
CWE-502 CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
jenkins jenkins *
jenkins jenkins *
redhat openshift_container_platform 3.11

GitHub Security Advisory GHSA-hhpm-5cp2-hg4x

Deserialization of Untrusted Data in Jenkins

maven org.jenkins-ci.main:jenkins-core <= 2.138.3 Fixed: 2.138.4
maven org.jenkins-ci.main:jenkins-core >= 2.140, <= 2.153 Fixed: 2.154

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 98.33%

Top 0% most likely to be exploited

Threat Score 98.7 / 100

CISA Known Exploited

Date Added: 2022-02-10
Due Date: 2022-08-10
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub