PT-2018-5166 · Cloudbees+1 · Jenkins

Publicado

2018-01-29

·

Atualizado

2022-05-14

·

CVE-2017-1000355

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.56 and earlier Jenkins version 2.46.1 LTS and earlier
Description The issue concerns an XStream-related Java crash that occurs when attempting to instantiate void/Void, leading to a potential disruption in service.
Recommendations For Jenkins versions 2.56 and earlier, update to a version later than 2.56 to resolve the issue. For Jenkins version 2.46.1 LTS and earlier, update to a version later than 2.46.1 LTS to resolve the issue.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000355
GHSA-4466-8JM4-448P

Produtos afetados

Jenkins