CVE-2015-8103
critical · 9.8The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groovy variant in 'ysoserial'".
9.8
CVSS
86.7%
EPSS (exploit prob.)
100th
EPSS percentile
2015-11-25
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redhat | openshift_container_platform | 2.2 |
| redhat | openshift_container_platform | 3.1 |
| jenkins | jenkins | < 1.625.2 |
| jenkins | jenkins | < 1.638 |
Check a specific version with /api/v1/cve/match.
References
- http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#jenkins
- http://packetstormsecurity.com/files/134805/Jenkins-CLI-RMI-Java-Deserialization.html
- http://rhn.redhat.com/errata/RHSA-2016-0489.html
- http://www.openwall.com/lists/oss-security/2015/11/09/5
- http://www.openwall.com/lists/oss-security/2015/11/18/11
- http://www.openwall.com/lists/oss-security/2015/11/18/13
- http://www.openwall.com/lists/oss-security/2015/11/18/2
- http://www.securityfocus.com/bid/77636
- https://access.redhat.com/errata/RHSA-2016:0070
- https://jenkins-ci.org/content/mitigating-unauthenticated-remote-code-execution-0-day-jenkins-cli
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
- https://www.exploit-db.com/exploits/38983/
- http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#jenkins
- http://packetstormsecurity.com/files/134805/Jenkins-CLI-RMI-Java-Deserialization.html
- http://rhn.redhat.com/errata/RHSA-2016-0489.html
- http://www.openwall.com/lists/oss-security/2015/11/09/5
- http://www.openwall.com/lists/oss-security/2015/11/18/11
- http://www.openwall.com/lists/oss-security/2015/11/18/13
- http://www.openwall.com/lists/oss-security/2015/11/18/2
- http://www.securityfocus.com/bid/77636
- https://access.redhat.com/errata/RHSA-2016:0070
- https://jenkins-ci.org/content/mitigating-unauthenticated-remote-code-execution-0-day-jenkins-cli
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
- https://www.exploit-db.com/exploits/38983/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-8103