Executive brief
A deserialization of untrusted data vulnerability in the Stapler web framework used by Jenkins allows remote attackers to invoke unintended methods on Java objects via crafted URLs. This can lead to arbitrary code execution on the affected Jenkins server.
Affected products
- Jenkins Jenkins 2.153 and earlier
- Jenkins Jenkins LTS 2.138.3 and earlier
- Jenkins Stapler all versions prior to fix
Timeline
- 2018-12-05: advisory: Vendor security advisory published by Jenkins.
- 2018-12-10: disclosed: NVD Published Date.
- 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.