CVE-2018-1000861

Description

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.467

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 2.153Windows
Vulnerabilities CVE-2018-1000862,CVE-2018-1000864,CVE-2018-1000863,CVE-2018-1000861 are fixed in Jenkins-Core 2.138.4Windows
Vulnerabilities CVE-2018-1000862,CVE-2018-1000864,CVE-2018-1000863,CVE-2018-1000861 are fixed in Jenkins-Core 2.154Windows
Multiple vulnerabilities affected in Jenkins 2.153 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 2.153 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 2.153 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 2.153 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 2.153 (For Suse)Linux
Vulnerabilities CVE-2018-1000862,CVE-2018-1000864,CVE-2018-1000863,CVE-2018-1000861 are fixed in Jenkins-Core for Linux 2.138.4Linux
Vulnerabilities CVE-2018-1000862,CVE-2018-1000864,CVE-2018-1000863,CVE-2018-1000861 are fixed in Jenkins-Core for Linux 2.154Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234