jenkins: Unauthenticated remote code execution (SECURITY-429)
Published Jan 29, 2018 ·Due Oct 23, 2025
9.8
CRITICALCVSS 3.1
EPSS 99.68%
Description
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.
Affected products
No data.
No data.
Red Hat OpenShift Enterprise 2
jenkins
Will not fix
Red Hat OpenShift Enterprise 3
jenkins
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Enterprise 2 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Enterprise 3 | jenkins | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- http://packetstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-Code-Execution.html x_refsource_MISCPermissions RequiredThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/98056 vdb-entryx_refsource_BIDBroken Link
- https://access.redhat.com/security/cve/CVE-2017-1000353 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1446114 Issue Tracking
- https://github.com/advisories/GHSA-26wc-3wqp-g3rp Advisory
- https://github.com/jenkinsci/jenkins/commit/36b8285a41eb28333549e8d851f81fd80a184076
- https://github.com/jenkinsci/jenkins/commit/f237601afd750a0eaaf961e8120b08de238f2c3f
- https://jenkins.io/security/advisory/2017-04-26 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000353
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-1000353 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2017-1000353
- https://www.exploit-db.com/exploits/41965 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.