CVE-2015-8103 is an unsafe deserialization vulnerability in the Jenkins CLI subsystem affecting Jenkins before 1.638 and Jenkins LTS before 1.625.2. The flaw allows a remote attacker to supply a crafted serialized Java object to the CLI component, which deserializes untrusted data without adequate validation. Exploitation is associated with gadget chains available through Apache Commons Collections classes present in Jenkins, including the Groovy-based ysoserial variant referenced in public reporting. Successful exploitation can trigger arbitrary code execution during deserialization within the Jenkins process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'jenkins_java_deserialize.rb', which exploits CVE-2015-8103, a Java deserialization vulnerability in Jenkins (version 1.637 and below). The exploit leverages the Jenkins CLI RMI endpoint to achieve unauthenticated remote code execution by sending a malicious serialized Java object. The module is highly weaponized, allowing the attacker to select and deliver arbitrary Metasploit payloads (such as command or shell) to the target. The exploit requires network access to the Jenkins HTTP port (default 8080) and optionally the CLI port, which is discovered via the 'X-Jenkins-CLI-Port' HTTP header. The payload is written to a temporary directory (default /tmp) on the target. The code is structured as a typical Metasploit module, with options for target URI, temporary directory, and port configuration. The module is operational and ready for use within the Metasploit framework.
This repository contains a single Metasploit module (modules/exploits/linux/misc/opennms_java_serialize.rb) that exploits a Java object deserialization vulnerability (CVE-2015-8103) in OpenNMS. The exploit targets the Java RMI service (default port 1099) exposed by OpenNMS on Linux systems. It works by sending a malicious serialized object to the RMI service, which triggers arbitrary code execution. The module sets up an HTTP server to host a payload (typically a reverse shell or meterpreter ELF binary), instructs the target to download it via wget to a writable directory (default /tmp/), makes it executable, and then runs it. The exploit is fully weaponized, allowing the attacker to select and customize payloads using the Metasploit framework. The only file in the repository is the exploit module itself, written in Ruby and structured according to Metasploit conventions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An observed example related to CWE-913 involving a deserialization issue in a commonly used Java library that allows remote execution.
Jenkinsにおけるデシリアライズ関連のコード実行脆弱性として比較例で言及。
Deserialization vulnerability in a commonly used Java library that allows remote code execution.
A Java deserialization vulnerability in a widely used Java library that can allow remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.