target entity

Jenkins

6 source-linked records in the current knowledge graph.

high

CVE-2017-1000353: Jenkins Remote Code Execution Vulnerability

Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2017-1000353EPSS 99.7%Jenkins
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23897: Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23897EPSS 100.0%JenkinsJenkins Command Line Interface (CLI)
CISA KEV ↗ · unattributed attribution