Jenkins 2.153 and earlier and LTS 2.138.3 and earlier are susceptible to a remote command injection via stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
id: CVE-2018-1000861
info:
name: Jenkins - Remote Command Injection
author: dhiyaneshDK,pikpikc
...