CVE-2015-8103: Jenkins
Critical severity, CVSS 9.8. EPSS: 86.7% chance of exploitation in the next 30 days.
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groovy variant in 'ysoserial'".
Affected products
- Jenkins Jenkins: before 1.625.2 (fixed in 1.625.2); before 1.638 (fixed in 1.638)
- Red Hat Openshift Container Platform: version 2.2 only; version 3.1 only
Published 2015-11-25. Last modified 2026-06-17.