CVE-2017-1000353 is a critical unauthenticated remote code execution vulnerability affecting Jenkins versions 2.56 and earlier, and 2.46.1 LTS and earlier. Attackers could exploit this by sending a specially crafted serialized Java SignedObject object to the Jenkins CLI, bypassing existing security mechanisms. With a CVSS score of 9.8, this vulnerability allows for complete compromise of confidentiality, integrity, and availability without requiring any authentication or user interaction. It is actively exploited in the wild, with readily available exploit modules in Metasploit and Nuclei, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.56CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* | ||
<= 2.46.1CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.