VYPR
Critical severityCISA KEVNVD Advisory· Published Dec 10, 2018· Updated Oct 21, 2025

CVE-2018-1000861

CVE-2018-1000861

Description

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.main:jenkins-coreMaven
< 2.138.42.138.4
org.jenkins-ci.main:jenkins-coreMaven
>= 2.140, < 2.1542.154

Affected products

1

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.