CVE-2016-9299

Description

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
86.028

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 2.31Windows
Vulnerabilities CVE-2016-9299 are fixed in Jenkins-Core 2.32Windows
Vulnerabilities CVE-2016-9299 are fixed in Jenkins-Core 2.19.3Windows
Multiple vulnerabilities affected in Jenkins 2.31 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 2.31 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 2.31 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 2.31 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 2.31 (For Suse)Linux
Vulnerabilities CVE-2016-9299 are fixed in Jenkins-Core for Linux 2.32Linux
Vulnerabilities CVE-2016-9299 are fixed in Jenkins-Core for Linux 2.19.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234