CVE-2017-2608: High severity jenkins lts vulnerability
Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.imageio in XStream-based APIs (SECURITY-383).
Other sources
The following flaw was found in Jenkins:
XStream-based APIs in Jenkins (e.g. /createItem URLs, or POST config.xml remote API) were vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.imageio.
In case this extension of the blacklist results in regressions, the blacklist can be customized as described in the Jenkins LTS upgrade guide for Jenkins 2.19.3.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2017-02-01
Upstream patch:
https://github.com/jenkinsci/jenkins/commit/a814154695e23dc37542af7d40cacc129cf70722
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2608?
CVE-2017-2608 is classified as a high severity remote code execution vulnerability.
How do I fix CVE-2017-2608?
To fix CVE-2017-2608, upgrade Jenkins to versions 2.44 or later, or 2.32.2 or later.
What types of systems are affected by CVE-2017-2608?
CVE-2017-2608 affects Jenkins versions prior to 2.44 and 2.32.2 across various installations.
What is the nature of the vulnerability in CVE-2017-2608?
CVE-2017-2608 involves remote code execution due to insecure deserialization in XStream-based APIs.
Can CVE-2017-2608 be exploited remotely?
Yes, CVE-2017-2608 can be exploited remotely by an unauthenticated attacker.