Description
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2014-6483 Vulnerability (CVE-2014-6483)
Atlassian Jira Insufficient Session Expiration Vulnerability (CVE-2021-39113)
WordPress Plugin WordPress File Upload Directory Traversal (4.12.2)
WebLogic CVE-2019-2647 Vulnerability (CVE-2019-2647)
WordPress Plugin Duplicate Page and Post SQL Injection (2.5.6)