RULE(RULE ID:337952)

Rule General Information
Release Date: 2024-04-23
Rule Name: Jenkins Remote Code Execution Vulnerability (CVE-2018-1000861)
Severity:
CVE ID:
Rule Protection Details
Description: A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:106176
SecurityFocusBID:106176
https://packetstormsecurity.com/files/166778/Jenkins-Remote-Code-Execution.html
https://jenkins.io/security/advisory/2018-12-05/
Solutions
Refer to the announcement or patch by the vendor: https://jenkins.io/security/advisory/2018-12-05/