Jenkins - SECURITY-200 / CVE-2015-5323 PoC
API tokens of other users available to admins
SECURITY-200 / CVE-2015-5323
API tokens of other users were exposed to admins by default. On instances that don’t implicitly grant RunScripts permission to admins, this allowed admins to run scripts with another user’s credentials.
受影响的版本
- 所有Jenkins主线版本,包括1.637及以下
- 所有Jenkins LTS版本,包括1.625.1及以下
PoC
在Jenkins 1.6.37上测试
从脚本控制台运行以下Groovy代码获取其他用户的令牌:
|
|
标签 devops, jenkins, Pentesting