V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2017-1000353
DEB
High KEVConfirmedExploit available

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthen…

CVSS
8.1
High
EPSS
0.94
p99
Published
2017-01-01
Updated
2025-10-02
Description

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.

Tags · CWE
KEVPre-auth
CWE-502
CAPEC-586
Affected products
Communications_cloud_native_core_automated_test_suite
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2017-01-01
Published
2025-10-02
Added to KEV
2025-10-02
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.945 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
41965
exploitdb · https://www.exploit-db.com/exploits/41965
Enterprise
CVE-2017-1000353
github-poc · https://github.com/r00t4dm/Jenkins-CVE-2017-1000353
Enterprise
Affected software
ProductVendorStatus
jenkinsExploited
communications_cloud_native_core_automated_test_suite*Exploited
jenkins*Exploited
jenkins*Exploited
Source databases
DEB
CVE
Related vulnerabilities