RULE(RULE ID:710398)

Rule General Information
Release Date: 2016-08-17
Rule Name: Jenkins CI Server Commons-collections Library Insecure Deserialization Vulnerability -2 (CVE-2015-8103)
Severity:
CVE ID:
Rule Protection Details
Description: The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groovy variant in 'ysoserial'".
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Mac OS, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:77636
ExploitDB:38983
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11