CVE-2018-1000861 is a critical code execution vulnerability in the Stapler web framework used by Jenkins 2.153 and earlier, and LTS 2.138.3 and earlier. This flaw allows unauthenticated attackers to invoke unintended methods on Java objects via crafted URLs, affecting Jenkins and Red Hat OpenShift Container Platform. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, with public Metasploit modules and Nuclei templates available, and has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.138.3CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
<= 2.153CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* | ||
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.