PT-2018-5166 · Cloudbees+1 · Jenkins

Published

2018-01-29

·

Updated

2022-05-14

·

CVE-2017-1000355

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.56 and earlier Jenkins version 2.46.1 LTS and earlier
Description The issue concerns an XStream-related Java crash that occurs when attempting to instantiate void/Void, leading to a potential disruption in service.
Recommendations For Jenkins versions 2.56 and earlier, update to a version later than 2.56 to resolve the issue. For Jenkins version 2.46.1 LTS and earlier, update to a version later than 2.46.1 LTS to resolve the issue.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000355
GHSA-4466-8JM4-448P

Affected Products

Jenkins