Janusz Piechówka

2 exploits Active since Apr 2016
CVE-2016-0792 NOMISEC HIGH WORKING POC
Jenkins XStream Groovy classpath Deserialization Vulnerability
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.
1 stars
CVSS 8.8
CVE-2016-0792 EXPLOITDB HIGH python WORKING POC
Jenkins XStream Groovy classpath Deserialization Vulnerability
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.
CVSS 8.8