Jenkins - SECURITY-200 / CVE-2015-5323 PoC
API tokens of other users available to admins
SECURITY-200 / CVE-2015-5323
API tokens of other users were exposed to admins by default. On instances that don’t implicitly grant RunScripts permission to admins, this allowed admins to run scripts with another user’s credentials.
受影响版本
- All Jenkins main line releases up to and including 1.637
- All Jenkins LTS releases up to and including 1.625.1
PoC
Tested against Jenkins 1.6.37
From the script console:
|
|
标签 devops, jenkins, Pentesting