Skip to content
COOEY

EXPOSURES › CVE-2018-1000861

CVE-2018-1000861

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-02-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-1000861 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Jenkins Stapler Web Framework suffered a deserialization of untrusted data vulnerability allowing remote code execution.

The Jenkins Stapler Web Framework contained a deserialization of untrusted data vulnerability that allowed attackers to execute arbitrary code remotely. This failure is highly relevant to DIB organizations because Jenkins is widely used for CI/CD pipelines, and a compromise could lead to supply chain attacks, credential theft, or deployment of malicious artifacts. Organizations must ensure Jenkins and its plugins are patched to the latest versions and restrict deserialization of untrusted data in their pipelines.

Shame score — A known deserialization vulnerability in a widely used CI/CD framework was left unpatched long enough to be actively exploited in the wild, demonstrating negligence in maintaining critical infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A code execution vulnerability exists in the Stapler web framework used by Jenkins

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.