Exploited Vulnerabilities Daily
🌐 日本語

ホーム › Jenkins

CVE-2017-1000353: Jenkins Jenkins

EPSS99.6%KEV 1739件中172位
CVEの年2017追加まで約8年
同じベンダーの登録6
同じ製品の登録1
項目内容
ベンダーJenkins
製品Jenkins
脆弱性の名前Jenkins Remote Code Execution Vulnerability
KEVへの追加日2025年10月2日
米政府機関の対応期限2025年10月23日
ランサムウェアでの悪用不明
CWE–

CISAの説明(英語)

Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.

NVD — CVE-2017-1000353

CISAの既知の悪用された脆弱性カタログ(KEV)のデータです。EPSSはFIRSTが公表する「今後30日以内に悪用が観測される確率」の推定値で、週1回更新しています。対応は必ず各ベンダーの公式情報に従ってください。
このページについて

2025年10月2日にCISAの既知の悪用された脆弱性カタログ(KEV)に追加された、JenkinsのJenkinsの脆弱性です。