← Back to browse · API

CVE-2018-1000861

Severity
CRITICAL
CVSS
9.8
EPSS
0.98326
Risk score
59.41
CISA KEV
Yes
PoC
No
Published
2018-12-10
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-4161, GHSA-HHPM-5CP2-HG4X
Products
Jenkins:Jenkins Stapler Web Framework, n/a:n/a n/a
Sources
cisa.gov CVE-2018-1000861
euvd EUVD-2022-4161

Description

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

References