CVE-2016-0788: Critical severity jenkins lts vulnerability
The following flaw was found in Jenkins:
A vulnerability in the Jenkins remoting module allowed unauthenticated remote attackers to open a JRMP listener on the server hosting the Jenkins master process, which allowed arbitrary code execution.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Other sources
The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0788?
CVE-2016-0788 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2016-0788?
To fix CVE-2016-0788, upgrade Jenkins to version 1.650 or later, or LTS version 1.642.2 or later.
What software versions are affected by CVE-2016-0788?
CVE-2016-0788 affects Jenkins versions prior to 1.650 and LTS versions prior to 1.642.2.
Can CVE-2016-0788 be exploited remotely?
Yes, CVE-2016-0788 allows unauthenticated remote attackers to execute arbitrary code.
What impact does CVE-2016-0788 have on system security?
CVE-2016-0788 poses a significant security risk as it enables remote attackers to gain control over the Jenkins server.