Description
The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.
Remediation
References
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
https://access.redhat.com/errata/RHSA-2016:0711
http://rhn.redhat.com/errata/RHSA-2016-1773.html
Related Vulnerabilities
CVE-2022-24785 Vulnerability in maven package org.fujion.webjars:moment
CVE-2023-41037 Vulnerability in npm package openpgp
CVE-2022-0198 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp
CVE-2021-21118 Vulnerability in maven package org.webjars.npm:electron
CVE-2016-1000340 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on