CVE-2017-2608: Jenkins

High severity, CVSS 8.8. EPSS: 6% chance of exploitation in the next 30 days.

Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.imageio in XStream-based APIs (SECURITY-383).

Affected products

  • Jenkins Jenkins: up to and including 2.44; before 2.32.2 (fixed in 2.32.2)

Published 2018-05-15. Last modified 2026-06-17.