4
CVSSv2

CVE-2017-1000355

Published: 29/01/2018 Updated: 15/02/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Jenkins versions 2.56 and previous versions as well as 2.46.1 LTS and previous versions are vulnerable to an XStream: Java crash when trying to instantiate void/Void.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

Vendor Advisories

Jenkins versions 256 and earlier as well as 2461 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void ...
Jenkins uses the XStream library to serialize and deserialize XML Its maintainer recently published a security vulnerability that allows anyone able to provide XML to Jenkins for processing using XStream to crash the Java process In Jenkins this typically applies to users with permission to create or configure items (jobs), views, or agents Jen ...