{"id":"CVE-2016-9299","description":"The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.","cvssScore":9.8,"cvssVersion":"3.0","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.0","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-90"],"resolved":"MITIGATION-CANDIDATE","published":"2017-01-12","lastModified":"2026-06-17","affectedProducts":[{"vendor":"jenkins","product":"jenkins","versionEnd":"\u003c=2.19.2"},{"vendor":"jenkins","product":"jenkins","versionEnd":"\u003c=2.31"},{"vendor":"fedoraproject","product":"fedora","version":"25"}],"totalAffectedProducts":2,"references":[{"url":"https://github.com/jenkinsci/jenkins/commit/6078dd7aa097baf3402de9d5279f6053926a1ea7","source":"osv","tags":["WEB"]},{"url":"https://github.com/jenkinsci/jenkins/commit/ce8a2d51a5ee9ca12d0a75659b06161888e0a1bf","source":"osv","tags":["WEB"]},{"url":"https://github.com/jenkinsci/jenkins/commit/d84d9a2ad3825f316f805a18b3654b0803e0d7fc","source":"osv","tags":["WEB"]},{"url":"https://github.com/jenkinsci/jenkins/commit/f574224cae5ffde2bc4c996305c0dcf5ab135440","source":"osv","tags":["WEB"]},{"url":"https://github.com/jenkinsci/jenkins/commit/fde9c42fe05ac925a904b6c09a81d497d0e6ccea","source":"osv","tags":["WEB"]},{"url":"https://github.com/jenkinsci/jenkins","source":"osv","tags":["PACKAGE"]},{"url":"https://groups.google.com/forum/#!original/jenkinsci-advisories/-fc-w9tNEJE/GRvEzWoJBgAJ","source":"osv","tags":["WEB"]},{"url":"https://groups.google.com/forum/#!original/jenkinsci-advisories/-fc-w9tNEJE/LZ7EOS0fBgAJ","source":"osv","tags":["WEB"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZW2KUKYLNLVDB7STLHLYALCUFLEGCRM6","source":"osv","tags":["WEB"]},{"url":"https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-11-16","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"open-source-maven","decidingReason":"This CVE affects an open-source Java library published on Maven Central (Maven packages: org.jenkins-ci.main:jenkins-core), so it is squarely in ARMR's territory and the source needed to understand the defect is public. That makes it a candidate for an ARMR patch rule. No rule exists and none is scheduled: the diff between the affected and fixed versions has not been read, and a closer look may find no hook point ARMR can act on.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.jenkins-ci.main:jenkins-core"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.jenkins-ci.main:jenkins-core). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written.","decisive":true},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is CRITICAL — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"no-match","detail":"A KEV listing, a CISA verdict of active exploitation, or a reviewed exploit catalogue carries this CVE — somebody has published a working exploit, so it stays a candidate"}],"affectedProducts":[{"vendor":"jenkins","product":"jenkins","isKnown":false,"cpe":"cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*"},{"vendor":"fedoraproject","product":"fedora","isKnown":false,"cpe":"cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.jenkins-ci.main:jenkins-core","introduced":"2.20","fixed":"2.32"},{"name":"org.jenkins-ci.main:jenkins-core","introduced":"0","fixed":"2.19.3"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"inferred"}},"exploits":[{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/44642","title":"Jenkins CLI - HTTP Java Deserialization (Metasploit)","date":"2018-05-17"},{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/44642","title":"Jenkins CLI - HTTP Java Deserialization (Metasploit)","date":"2018-05-17"},{"source":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2016/CVE-2016-9299.yaml","title":"Jenkins CLI - HTTP Java Deserialization"}],"signals":{"hasPOC":true,"pocCount":3,"pocSources":["exploit-db","nuclei"],"firstPOCDate":"2018-05-17"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.96943,"percentile":0.99887},"ssvc":{"available":false}}