CVE-2018-1000861
Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 August 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 98.33% probability · 100th percentile
- CISA KEV
- Listed 10 February 2022 · due 10 August 2022
- Weakness
- CWE-502
- Affected
- jenkins/jenkins · redhat/openshift container platform
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-1000861
References
- http://packetstormsecurity.com/files/166778/Jenkins-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/106176Broken Link
- https://access.redhat.com/errata/RHBA-2019:0024Third Party Advisory
- https://jenkins.io/security/advisory/2018-12-05/#SECURITY-595Vendor Advisory
- http://packetstormsecurity.com/files/166778/Jenkins-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/106176Broken Link
- https://access.redhat.com/errata/RHBA-2019:0024Third Party Advisory
- https://jenkins.io/security/advisory/2018-12-05/#SECURITY-595Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1000861US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.