Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Oct 23, 2025

High
CISA KEV

CVE-2017-1000353

JenkinsJenkins

Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.

Required Action

https://www.jenkins.io/security/advisory/2017-04-26/ ; https://nvd.nist.gov/vuln/detail/CVE-2017-1000353

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Unknown
Published
Oct 2, 2025
KEV Added
Oct 2, 2025
Due Date
Oct 23, 2025
Related Articles
0

Vendor

Jenkins

Jenkins