
Vulnerability
Jenkins is an open-source automation server that is free to use. It is a server-side application that runs in servlet containers like Apache Tomcat.In stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java, a code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier that allows attackers to call some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
Mitigation / Precaution
In order to patch this vulnerability, please install the official patch Jenkins made available for supported, vulnerable instances.
Summarize:
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days





