Jenkins is an open-source automation server that is free to use. It is a server-side application that runs in servlet containers like Apache Tomcat.In stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java, a code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier that allows attackers to call some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
In order to patch this vulnerability, please install the official patch Jenkins made available for supported, vulnerable instances.