Vulnerability record · CVE-2017-1000353 · published 29 January 2018
CVE-2017-1000353: Jenkins CLI Java deserialization allows unauthenticated remote code execution
Jenkins · Jenkins
Jenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the existing blacklist-based protection. Because the flaw is reachable without authentication, it exposes Jenkins controllers to full remote code execution.
Description
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with CVSS 9.8, KEV listing and near-maximum EPSS makes this an urgent patch-first issue.
What it is
Jenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the existing blacklist-based protection. Because the flaw is reachable without authentication, it exposes Jenkins controllers to full remote code execution.
Impact
An unauthenticated attacker can execute arbitrary code on the Jenkins controller, leading to full compromise of the CI/CD server and any credentials or build secrets it holds.
Attack surface
Reached over the network through the Jenkins CLI (remoting/Java serialization protocol) on the affected versions. The CVSS vector shows no privileges and no user interaction required.
Exploitation
CISA added it to KEV on 2025-10-02 with a 2025-10-23 due date, and EPSS is 0.99679 (99.95th percentile); public exploit code is referenced (ExploitDB 41965), though no ransomware campaign use is documented.
What to do
- Upgrade Jenkins to a fixed release (2.57 or later, or 2.46.2 LTS or later) that blacklists SignedObject and backports the HTTP CLI protocol.
- Disable or restrict the remoting-based (Java serialization) CLI protocol, which is disabled by default in fixed versions.
- Block network access to the Jenkins CLI/remoting port from untrusted networks; expose only the HTTP CLI where possible.
- If immediate upgrade is not possible, apply vendor mitigations or discontinue use of the affected product per CISA BOD 22-01 guidance.
- Rotate credentials and secrets stored in Jenkins after any suspected exposure.
Detection
- Monitor network traffic to the Jenkins CLI/remoting port for unexpected external connections.
- Inspect Jenkins logs for CLI connection and deserialization errors or unusual SignedObject handling.
- Hunt for unexpected child processes spawned by the Jenkins Java process (e.g., shells, curl, wget).
- Alert on outbound connections from the Jenkins controller to unknown hosts following CLI activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-1000353 to the Known Exploited Vulnerabilities catalog on 2 October 2025 as "Jenkins Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 October 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-Code-Execution.html | Permissions RequiredThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/98056 | Broken Link |
| https://jenkins.io/security/advisory/2017-04-26/ | Vendor Advisory |
| https://www.exploit-db.com/exploits/41965/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| http://packetstormsecurity.com/files/159266/Jenkins-2.56-CLI-Deserialization-Code-Execution.html | Permissions RequiredThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/98056 | Broken Link |
| https://jenkins.io/security/advisory/2017-04-26/ | Vendor Advisory |
| https://www.exploit-db.com/exploits/41965/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-1000353 | US Government Resource |
Track CVE-2017-1000353 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-1000353), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.