The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groovy variant in 'ysoserial'".
CVE-2015-8103
Score elevated to 9.8 because EPSS predicts 87% probability of exploitation within the next 30 days (top 0.3% of all CVEs). NVD baseline CVSS 9.8 retained for reference. Confidence: see factors.
- 11 internet-exposed hosts are running an affected version right now
- High exploitation likelihood — EPSS 87%
A fix is available — apply it.
11 internet-exposed hosts are running an affected version of CVE-2015-8103 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EPSS
- 99.7%
- KEV
- Not listed
Published
November 25, 2015
Last Modified
May 6, 2026
Advisory Details (10)
Auto-updated May 7, 2026oss-security - Re: CVE request: Jenkins remote code execution vulnerability due to unsafe deserialization
http://www.openwall.com/lists/oss-security/2015/11/18/2oss-security - Re: CVE request: Jenkins remote code execution vulnerability due to unsafe deserialization
http://www.openwall.com/lists/oss-security/2015/11/18/13oss-security - Re: Re: CVE request: Jenkins remote code execution vulnerability due to unsafe deserialization
http://www.openwall.com/lists/oss-security/2015/11/18/11oss-security - CVE request: Jenkins remote code execution vulnerability due to unsafe deserialization
http://www.openwall.com/lists/oss-security/2015/11/09/5Packet Storm
http://packetstormsecurity.com/files/134805/Jenkins-CLI-RMI-Java-Deserialization.htmlWhat Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability.
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#jenkinsVendor Advisories for CVE-2015-8103(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(2)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | rubygem-openshift-origin-node-0:1.38.5.3-1.el6op | 2016-03-22 | redhat |
| redhat | origin-kibana-0:0.5.0-1.el7aos | 2016-01-26 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.jenkins-ci.main:cli | 1.626 ... 1.637 (12 versions) | 1.638 | — |
Additional Vendor Advisories
(1)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 8× in last 7d / 18× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 21:59 UTCEG score recompute
- 2026-07-22 14:04 UTCEPSS rescore
- 2026-07-21 15:21 UTCEPSS rescore
- 2026-07-21 15:21 UTCEPSS rescore
- 2026-07-19 14:27 UTCEPSS rescore
- 2026-07-19 14:27 UTCEPSS rescore
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-15 16:54 UTCEPSS rescore
- 2026-07-15 16:54 UTCEPSS rescore
- 2026-07-12 05:42 UTCEPSS rescore
- 2026-07-04 06:28 UTCEPSS rescore
- 2026-06-30 23:19 UTCEPSS rescore
- 2026-06-30 23:19 UTCEPSS rescore
- 2026-06-27 03:05 UTCEPSS rescore
- 2026-06-24 14:02 UTCEPSS rescore
- 2026-06-24 14:02 UTCEPSS rescore
- 2026-06-23 21:30 UTCEPSS rescore
- 2026-06-18 17:50 UTCEPSS rescore
- 2026-06-17 17:50 UTCEPSS rescore
- 2026-06-17 17:49 UTCEPSS rescore
- 2026-06-15 17:45 UTCEPSS rescore
- 2026-06-13 22:57 UTCEPSS rescore
- 2026-06-12 23:09 UTCEPSS rescore
- 2026-06-12 23:09 UTCEPSS rescore
Show 32 moreShow fewer
- 2026-06-11 13:57 UTCEPSS rescore
- 2026-06-11 13:57 UTCEPSS rescore
- 2026-06-10 13:18 UTCEPSS rescore
- 2026-06-08 14:14 UTCEPSS rescore
- 2026-06-06 13:45 UTCEPSS rescore
- 2026-06-05 22:44 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-06-01 13:49 UTCEPSS rescore
- 2026-06-01 13:49 UTCEPSS rescore
- 2026-05-31 00:14 UTCEPSS rescore
- 2026-05-29 13:41 UTCEPSS rescore
- 2026-05-28 13:42 UTCEPSS rescore
- 2026-05-28 13:42 UTCEPSS rescore
- 2026-05-26 13:41 UTCEPSS rescore
- 2026-05-22 21:15 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 09:47 UTCVendor advisory
- 2026-05-20 05:40 UTCVendor advisory
- 2026-05-20 01:33 UTCVendor advisory
- 2026-05-19 21:26 UTCVendor advisory
- 2026-05-19 17:19 UTCVendor advisory
- 2026-05-19 13:12 UTCVendor advisory
- 2026-05-19 09:05 UTCVendor advisory
- 2026-05-19 04:57 UTCVendor advisory
- 2026-05-19 00:50 UTCEG score recompute
- 2026-05-19 00:50 UTCVendor advisory
- 2026-05-18 21:30 UTCEPSS rescore
- 2026-05-18 21:30 UTCEPSS rescore
Publicly available exploits
(4 references)Working exploit code is in the public domain (3 Metasploit modules) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-38983✓ verifiedFirst seen Dec 15, 2015
Jenkins CLI - RMI Java Deserialization (Metasploit)
Open source ↗ - Metasploitexploit/linux/misc/jenkins_java_deserialize✓ verifiedFirst seen Nov 18, 2015
Jenkins CLI RMI Java Deserialization Vulnerability
Open source ↗ - Metasploitexploit/linux/misc/opennms_java_serialize✓ verifiedFirst seen Nov 6, 2015
OpenNMS Java Object Unserialization Remote Code Execution
Open source ↗ - Metasploitauxiliary/scanner/http/jenkins_command✓ verifiedFirst seen Jan 1, 2015
Jenkins-CI Unauthenticated Script-Console Scanner
Open source ↗
Related CVEs(same vendor)
Frequently asked(5)
What is CVE-2015-8103?
When was CVE-2015-8103 disclosed?
Is CVE-2015-8103 actively exploited?
What is the CVSS score of CVE-2015-8103?
How do I remediate CVE-2015-8103?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2015-8103
Is Your Infrastructure Affected by CVE-2015-8103?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.