CVE-2017-1000353
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 9.8epss 100%
de la publicación al arma0 días
Publicada en NVD29 ene
1ª PoC5 may
metasploit26 abr
CISA KEV+2803d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
síCISA + VulnCheck
7 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)
Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.
Red Hatdocumento VEX ↗
Afectado
1 producto
Red Hat OpenShift Enterprise 2
no_fix_planned: Will not fix
No afectado
1 producto (2 componentes) — porque el código vulnerable no está presente en el producto
Red Hat OpenShift Enterprise 3
Acción exigida por CISAplazo federal: 2025-10-23
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Versiones
Afectadas
maven/org.jenkins-ci.main:jenkins-core >= 2.50, <= 2.56; maven/org.jenkins-ci.main:jenkins-core <= 2.46.1
Corregidas en
maven/org.jenkins-ci.main:jenkins-core 2.57; maven/org.jenkins-ci.main:jenkins-core 2.46.2
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · n/aPoCs públicas encontradas — 7
exploitdbwww.exploit-db.com/exploits/41965no verificadogithubgithub.com/vulhub/CVE-2017-1000353★ 57githubgithub.com/r00t4dm/Jenkins-CVE-2017-1000353★ 3cve_referencewww.exploit-db.com/exploits/41965/no verificadovulncheckvulncheck.com/xdb/995894c2f1a6no verificadovulncheckvulncheck.com/xdb/b3a083a5a7fano verificadocve_referencepacketstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-Code-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-Code-Execution.htmlhttps://jenkins.io/security/advisory/2017-04-26/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-1000353https://www.exploit-db.com/exploits/41965/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://www.securityfocus.com/bid/98056