CISA Known Exploited Vulnerability

CVE-2018-1000861

Jenkins · Jenkins Stapler Web Framework

Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability

Date added
BOD 22-01 due date
CWE CWE-502
Ransomware Unknown

CISA description

A code execution vulnerability exists in the Stapler web framework used by Jenkins

Required action

Apply updates per vendor instructions.