Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000355
Reference (s):
- BID:98066
- URL: http://www.securityfocus.com/bid/98066
- https://jenkins.io/security/advisory/2017-04-26/

