RULE(RULE ID:323471)

Rule General Information
Release Date: 2019-10-10
Rule Name: Jenkins Remote Code Execution Vulnerability (CVE-2018-1000861 CVE-2019-1003030)
Severity:
CVE ID:
Rule Protection Details
Description: A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Others
Reference: SecurityFocusBID:106176
https://access.redhat.com/errata/RHBA-2019:0024
https://jenkins.io/security/advisory/2018-12-05/#SECURITY-595
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://jenkins.io/security/advisory/2018-12-05/#SECURITY-1193