CVE-2018-1000861: Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability
A code execution vulnerability exists in the Stapler web framework used by Jenkins
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.154 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.138.4
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000861?
CVE-2018-1000861 is classified as a high severity vulnerability due to its potential for code execution.
How do I fix CVE-2018-1000861?
To remediate CVE-2018-1000861, upgrade Jenkins to versions 2.154 or later, or 2.138.4 or later for LTS.
Which versions are affected by CVE-2018-1000861?
CVE-2018-1000861 affects Jenkins versions 2.153 and earlier, as well as LTS versions 2.138.3 and earlier.
What software uses the Stapler web framework vulnerable to CVE-2018-1000861?
The Stapler web framework vulnerable to CVE-2018-1000861 is used by Jenkins.
Is there a workaround for CVE-2018-1000861?
There is no official workaround for CVE-2018-1000861; upgrading to a secure version is recommended.