CVE Tools

Description

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

In plain language

AI Act now

CVE-2016-9299 is a serious Jenkins flaw where an outside attacker can send a specially crafted network message and run code on the server without logging in; most small businesses using Jenkins should treat this as urgent and upgrade.

Executive summary

CVE-2016-9299 is an unauthenticated remote code execution in the Jenkins remoting module (Java serialized object handling) for Jenkins before 2.32 and LTS before 2.19.3; a crafted serialized object triggers a lookup that can lead to arbitrary code execution.

If affected, business impact
Full Jenkins server takeoverMalware deployment on productionCredential and secret theftBuild pipeline compromise

What to do now

  1. Check whether you run Jenkins (or the Jenkins remoting module) and what version it is currently on.
  2. If your Jenkins version is earlier than 2.32 (or LTS earlier than 2.19.3), plan an immediate upgrade.
  3. Upgrade to the fixed release: Jenkins 2.32 or newer, or LTS 2.19.3 or newer.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

jenkins
oss-project·USaka jenkins ci
fedoraproject
oss-project·USaka fedora project
and 1 more affected products View all →

Exploitability

2 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 18 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2016-9299 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows