jenkins-core is vulnerable to Deserialization of Untrusted Data
88
High Risk
Transient fields cannot be excluded from deserialization during configuration updates. An attacker who can submit configuration updates can set transient field values that will be deserialized, with impact depending on how those fields are used. The fix adds a way to mark transient fields as non-deserializable so those values are ignored.
You are affected if you are using a version that falls within the vulnerable range and users can submit configuration updates that are deserialized by Jenkins.
jenkins-core is vulnerable to Deserialization of Untrusted Data in versions 0.0.1 - 2.568.2 and 2.569 - 2.579.
Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.