Debian has issued an advisory on May 2: https://www.debian.org/security/2017/dsa-3841 I don't know whether jenkins-xstream is affected. Mageia 5 is also affected.
CC: (none) => geiger.david68210Whiteboard: (none) => MGA5TOO
Fixed in cauldron
Version: Cauldron => 5Whiteboard: MGA5TOO => (none)
CVE: (none) => CVE-2017-7957
It sounds like CVE-2017-2608 affects jenkins, or jenkins-xstream, or xstream: http://openwall.com/lists/oss-security/2017/05/22/2
We won't be fixing this type of package for Mageia 5.
Resolution: (none) => OLDStatus: NEW => RESOLVED