CVE-2017-1000355

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
29/01/2018
Last modified:
15/02/2018

Description

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* 2.56 (including)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* 2.46.1 (including)