VDB
Sign up
CRITICAL9.8

GHSA-hhpm-5cp2-hg4x

Deserialization of Untrusted Data in Jenkins

Quick fix

GHSA-hhpm-5cp2-hg4x — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.138.4</version> for org.jenkins-ci.main:jenkins-core

Details

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jenkins-ci.main:jenkins-core
Introduced in: 0Fixed in: 2.138.4
Fix# pom.xml: bump <version>2.138.4</version> for org.jenkins-ci.main:jenkins-core
Maven/org.jenkins-ci.main:jenkins-core
Introduced in: 2.140Fixed in: 2.154
Fix# pom.xml: bump <version>2.154</version> for org.jenkins-ci.main:jenkins-core

References