1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. Attack: Jenkins JRMP Java Library Deserialization RCE 2

Attack: Jenkins JRMP Java Library Deserialization RCE 2

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects attempts to exploit remote privilege-escalation vulnerability.

Additional Information

Jenkins is prone to a remote code-execution vulnerability. Specifically, this issue affects the 'remoting' module. An attacker can exploit this issue by opening a 'JRMP' listener on the server hosting the Jenkins master process.

Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.

Affected

  • Jenkins before 1.650 and LTS before 1.642.2
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube