Jenkins has reported a significant security flaw that can enable attackers to run malicious code on the Jenkins controller by circumventing a security filter during agent-to-controller communications This article explores jenkins addressed vulnerability. . The issue has been assigned a Critical CVSS severity rating and impacts Jenkins 2.575 and earlier, as well as Jenkins LTS 2.568.1 and earlier.

Due to vulnerabilities in Java's deserialization capabilities, Jenkins implements JEP-200 class filtering when processing data sent via a Remoting channel. By leveraging an agent process control, code execution on an existing agent, or possessing Jenkins Agent/Connect permissions, an attacker can exploit this flaw to deserialize certain Java classes that should have been blocked.

However, controller-level code execution remains a critical risk due to potential exposure of source code, secrets, build credentials, deployment keys, and software supply chain pipelines. Jenkins addressed this vulnerability in advisory SECURITY-3911 with updates for versions 2.576 and 2.568.2, which enforce the JEP-200 class filter even when using the fallback deserialization path. Security teams must also evaluate which users, service accounts, and systems possess Agent/Connect permissions, as this access can facilitate exploitation paths.

Enhance your Security Operations Center (SOC) capabilities with ANY.RUN for faster threat detection and swift investigations.