QID 996909
Date Published: 2024-02-05
QID 996909: Java (Maven) Security Update for org.jenkins-ci.main:cli (GHSA-wfw7-6632-xcv2)
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groovy variant in ysoserial".
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wfw7-6632-xcv2 for updates and patch information.
Vendor References
- GHSA-wfw7-6632-xcv2 -
github.com/advisories/GHSA-wfw7-6632-xcv2
CVEs related to QID 996909
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wfw7-6632-xcv2 | org.jenkins-ci.main:cli |
|