Vulnerability Description
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Jenkins | <= 2.19.2 |
| Fedoraproject | Fedora | 25 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/11/12/4Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/14/9Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/94281Third Party AdvisoryVDB Entry
- http://www.slideshare.net/codewhitesec/java-deserialization-vulnerabilities-the-Third Party Advisory
- https://groups.google.com/forum/#%21original/jenkinsci-advisories/-fc-w9tNEJE/GR
- https://groups.google.com/forum/#%21original/jenkinsci-advisories/-fc-w9tNEJE/LZ
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-11-1Vendor Advisory
- https://www.cloudbees.com/jenkins-security-advisory-2016-11-16Vendor Advisory
- https://www.exploit-db.com/exploits/44642/Third Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2016/11/12/4Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/14/9Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/94281Third Party AdvisoryVDB Entry
- http://www.slideshare.net/codewhitesec/java-deserialization-vulnerabilities-the-Third Party Advisory
- https://groups.google.com/forum/#%21original/jenkinsci-advisories/-fc-w9tNEJE/GR
FAQ
What is CVE-2016-9299?
CVE-2016-9299 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party s...
How severe is CVE-2016-9299?
CVE-2016-9299 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-9299?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Jenkins, Fedoraproject Fedora.