CRITICAL9.8
GHSA-hhpm-5cp2-hg4x
Deserialization of Untrusted Data in Jenkins
Quick fix
GHSA-hhpm-5cp2-hg4x — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.138.4</version> for org.jenkins-ci.main:jenkins-coreDetails
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jenkins-ci.main:jenkins-core
Introduced in:
0Fixed in: 2.138.4Fix
# pom.xml: bump <version>2.138.4</version> for org.jenkins-ci.main:jenkins-coreMaven/org.jenkins-ci.main:jenkins-core
Introduced in:
2.140Fixed in: 2.154Fix
# pom.xml: bump <version>2.154</version> for org.jenkins-ci.main:jenkins-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000861[ADVISORY]
- https://github.com/jenkinsci/jenkins/commit/47f38d714c99e1841fb737ad1005618eb26ed852[WEB]
- https://access.redhat.com/errata/RHBA-2019:0024[WEB]
- https://jenkins.io/security/advisory/2018-12-05/#SECURITY-595[WEB]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1000861[WEB]
- http://packetstormsecurity.com/files/166778/Jenkins-Remote-Code-Execution.html[WEB]
- http://www.securityfocus.com/bid/106176[WEB]