peter bassill · operator
$ cve CVE-2016-0792 JSON

CVE-2016-0792 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 83.3% (pctl 100)

Patch early

A public exploit exists.

Description

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS83.26% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2016-04-07
Last modified2026-06-17

Affected (2)

VendorProduct
jenkinsjenkins
redhatopenshift

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD