Jenkins 2.150.2 Remote Command...

- AV AC AU C I A
发布: 2019-02-12
修订: 2025-04-13

This Metasploit module can run commands on the system using Jenkins users who has JOB creation and BUILD privileges. The vulnerability is exploited by a small script prepared in NodeJS. The sh parameter allows us to run commands. Sample script: node { sh "whoami" } In addition, ANONYMOUS users also have the authority to JOB create and BUILD by default. Therefore, all users without console authority can run commands on the system as root privilege.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息