cbcvebase.
CVE-2015-8103
published 2015-11-25

CVE-2015-8103: The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groovy variant in 'ysoserial'".

Affected

6 ranges
VendorProductVersion rangeFixed in
jenkinsjenkins< 1.625.21.625.2
jenkinsjenkins< 1.6381.638
jenkinsjenkins_core
jenkinsjenkins_lts
redhatopenshift_container_platform
redhatopenshift_container_platform