EXPOSURES › CVE-2018-1000861
CVE-2018-1000861
HIGH ⌖ ON CISA KEV · EXPLOITEDJenkins Stapler Web Framework suffered a deserialization of untrusted data vulnerability allowing remote code execution.
The Jenkins Stapler Web Framework contained a deserialization of untrusted data vulnerability that allowed attackers to execute arbitrary code remotely. This failure is highly relevant to DIB organizations because Jenkins is widely used for CI/CD pipelines, and a compromise could lead to supply chain attacks, credential theft, or deployment of malicious artifacts. Organizations must ensure Jenkins and its plugins are patched to the latest versions and restrict deserialization of untrusted data in their pipelines.
Shame score — A known deserialization vulnerability in a widely used CI/CD framework was left unpatched long enough to be actively exploited in the wild, demonstrating negligence in maintaining critical infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A code execution vulnerability exists in the Stapler web framework used by Jenkins