CVE-2016-9299
Description
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
In plain language
AI Act nowCVE-2016-9299 is a serious Jenkins flaw where an outside attacker can send a specially crafted network message and run code on the server without logging in; most small businesses using Jenkins should treat this as urgent and upgrade.
CVE-2016-9299 is an unauthenticated remote code execution in the Jenkins remoting module (Java serialized object handling) for Jenkins before 2.32 and LTS before 2.19.3; a crafted serialized object triggers a lookup that can lead to arbitrary code execution.
What to do now
- Check whether you run Jenkins (or the Jenkins remoting module) and what version it is currently on.
- If your Jenkins version is earlier than 2.32 (or LTS earlier than 2.19.3), plan an immediate upgrade.
- Upgrade to the fixed release: Jenkins 2.32 or newer, or LTS 2.19.3 or newer.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-9299 and every CVE in our database. Create a free account — no credit card required.
Create Free Account