Sploitus

CVE-2017-1000353

38 known exploits for CVE-2017-1000353

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.

Affected products
Jenkins
Jenkins
≤ 2.56
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
99.7% (100th percentile)
Weakness
CWE-502
NVD status
Analyzed
Published
2018-01-29
CVE-2017-1000353 at NVD
Authoritative description, scoring and affected products

38 known exploits for CVE-2017-1000353

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2017-1000353
2026-08-28 KitPloitKITPLOIT
Jenkins-CVE-2017-1000353
2026-08-27 KitPloitKITPLOIT
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2023-05-01 hundanGITEE
Exploit for SQL Injection in Zabbix
2022-01-19 天艺GITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-12-15 iceCreamGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-11-24 MOBGITEE
Exploit for SQL Injection in Zabbix
2021-11-13 三度的雪GITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-09-26 阿雷GITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-09-19 W3lk1nGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-08-15 d0ng1uGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-06-11 owlGITEE
Exploit for SQL Injection in Zabbix
2021-05-16 nullGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2021-03-29 wangnfcGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2021-01-18 sadfasdfGITEE
Exploit for Improper Input Validation in Redhat Openshift
2020-10-29 覆水之罪GITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-10-01 0xdawnGITEE
Jenkins 2.56 CLI Deserialization / Code Execution
2020-09-22 Shelby PacePACKETSTORMRuby
Jenkins 2.56 CLI Deserialization / Code Execution Exploit
2020-09-22 metasploitZDTRuby
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-07-30 orcnirnavaGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-07-28 小义的爸爸GITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-07-17 ZcocGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-07-12 AndyGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-07-10 aryaGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-06-18 Dawson_JonesGITEE
Exploit for Improper Input Validation in Redhat Openshift
2020-05-12 1024_ChinaGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-05-07 一个卿呀GITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-04-08 fahawifiGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2020-04-02 hhGITEE
Exploit for Improper Input Validation in Redhat Openshift
2020-03-10 vi3it0rGITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2020-02-04 AbelCheGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2019-10-31 morningGITEE
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2019-10-11 HFOUGITEE
Exploit for Deserialization of Untrusted Data in Jenkins
2019-04-12 vulhubGITHUB
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Gitlab
2018-08-21 老野战猪GITEE
Exploit for Improper Encoding or Escaping of Output in F5 Nginx
2018-08-03 warsongGITEE
CloudBees Jenkins 2.32.1 - Java Deserialization
2017-05-05 SecuriTeamEXPLOITDB
Jenkins Java Deserialization Remote Code Execution Vulnerability (CVE-2017-1000353)
2017-04-28 RootSEEBUG
Jenkins CLI Deserialization
2017-04-26 SSD, Unknown, Shelby PaceMETASPLOITRuby