← volver
CVE-2017-1000353criticalbajo ataqueCWE-502

CVE-2017-1000353

100Vexday Risk Score

Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.

ssvc Actcvss 9.8epss 100%
de la publicación al arma0 días
Publicada en NVD29 ene
1ª PoC5 may
metasploit26 abr
CISA KEV+2803d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
CISA + VulnCheck
7 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2025-10-23

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Versiones

Afectadas
maven/org.jenkins-ci.main:jenkins-core >= 2.50, <= 2.56; maven/org.jenkins-ci.main:jenkins-core <= 2.46.1
Corregidas en
maven/org.jenkins-ci.main:jenkins-core 2.57; maven/org.jenkins-ci.main:jenkins-core 2.46.2
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · n/a
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.