Lucene search

K
osvGoogleOSV:GHSA-2X9H-H3C4-WQQH
HistoryMay 14, 2022 - 1:00 a.m.

Improper Neutralization of Special Elements used in an LDAP Query in Jenkins

2022-05-1401:00:43
Google
osv.dev
16

0.633 Medium

EPSS

Percentile

97.9%

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

References