CVE-2018-1000861: Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-02-10. EPSS: 98.3% chance of exploitation in the next 30 days.

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

Affected products

  • Jenkins Jenkins: up to and including 2.138.3; up to and including 2.153
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2018-12-10. Last modified 2026-06-17.