HIGH 8.8 Maven

Jenkins allows Deserialization of Untrusted Data via an XML File

GHSA-45rg-g72w-r393 · CVE-2016-0792

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.

Ready to move

Start Securing

Free, no credit card | First findings in minutes