PT-2017-10042 · Cloudbees+1 · Jenkins

Alisa Esage

+1

·

Publicado

2016-11-30

·

Atualizado

2022-05-14

·

CVE-2016-9299

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.32 Jenkins LTS versions prior to 2.19.3
Description The issue allows remote attackers to execute arbitrary code via a crafted serialized Java object. This object triggers an LDAP query to a third-party server.
Recommendations For Jenkins versions prior to 2.32, update to version 2.32 or later. For Jenkins LTS versions prior to 2.19.3, update to version 2.19.3 or later.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9299
GHSA-2X9H-H3C4-WQQH
MGASA-2016-0406

Produtos afetados

Jenkins