← Vulnerability feed

Vulnerability record · CVE-2017-1000353 · published 29 January 2018

CVE-2017-1000353: Jenkins CLI Java deserialization allows unauthenticated remote code execution

Jenkins · Jenkins

Jenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the existing blacklist-based protection. Because the flaw is reachable without authentication, it exposes Jenkins controllers to full remote code execution.

9.8 CVSS 3.1 Critical CISA KEV since 2 Oct 2025 EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
11References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with CVSS 9.8, KEV listing and near-maximum EPSS makes this an urgent patch-first issue.

What it is

Jenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the existing blacklist-based protection. Because the flaw is reachable without authentication, it exposes Jenkins controllers to full remote code execution.

Impact

An unauthenticated attacker can execute arbitrary code on the Jenkins controller, leading to full compromise of the CI/CD server and any credentials or build secrets it holds.

Attack surface

Reached over the network through the Jenkins CLI (remoting/Java serialization protocol) on the affected versions. The CVSS vector shows no privileges and no user interaction required.

Exploitation

CISA added it to KEV on 2025-10-02 with a 2025-10-23 due date, and EPSS is 0.99679 (99.95th percentile); public exploit code is referenced (ExploitDB 41965), though no ransomware campaign use is documented.

What to do

  • Upgrade Jenkins to a fixed release (2.57 or later, or 2.46.2 LTS or later) that blacklists SignedObject and backports the HTTP CLI protocol.
  • Disable or restrict the remoting-based (Java serialization) CLI protocol, which is disabled by default in fixed versions.
  • Block network access to the Jenkins CLI/remoting port from untrusted networks; expose only the HTTP CLI where possible.
  • If immediate upgrade is not possible, apply vendor mitigations or discontinue use of the affected product per CISA BOD 22-01 guidance.
  • Rotate credentials and secrets stored in Jenkins after any suspected exposure.

Detection

  • Monitor network traffic to the Jenkins CLI/remoting port for unexpected external connections.
  • Inspect Jenkins logs for CLI connection and deserialization errors or unusual SignedObject handling.
  • Hunt for unexpected child processes spawned by the Jenkins Java process (e.g., shells, curl, wget).
  • Alert on outbound connections from the Jenkins controller to unknown hosts following CLI activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-1000353 to the Known Exploited Vulnerabilities catalog on 2 October 2025 as "Jenkins Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 October 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-1000353 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-23897Jenkins CLI parser arbitrary file read via @ path expansionJenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a fi…KEVEPSS 100%analysed9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2018-1000861Jenkins Stapler framework URL routing allows remote code executionThe Stapler web framework in Jenkins 2.153 and earlier and LTS 2.138.3 and earlier lets attackers invoke unintended Java methods by requesting crafte…KEVEPSS 98%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2015-5317Jenkins Fingerprints pages expose job and build namesJenkins before 1.638 and LTS before 1.625.2 expose sensitive job and build name information through the Fingerprints pages when requested directly. T…KEVEPSS 23%analysed9.8CVE-2021-21690Jenkins path traversal vulnerabilityAgent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2017-1000353), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.