Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Jenkins unauthorized access-arbitrary command execution

Shulou Source: shulou.com Published: 2022-06-01 06:46:49 10月03日 Update

Unauthorized access to jenkins-introduction to 0x00 jenkins for arbitrary command execution

Enkins is a powerful application that allows continuous integration and continuous delivery of projects, regardless of platform. This is a free source code that can handle any type of build or continuous integration. Integrated Jenkins can be used for some testing and deployment technologies. Jenkins is a piece of software that allows continuous integration.

Reasons for 0x01 vulnerabilities

Jenkins does not set the account password, or uses a weak account password

Recurrence of 0x02 vulnerabilities

By default, users in the Jenkins panel can choose to execute script interface to operate some system-level commands. Users can obtain server permissions through unauthorized access vulnerabilities or brute force cracking of user passwords into the script execution interface.

Any command execution interface:

Http://ip:port/script

Println "ifconfig". Execute (). Text

Tags: Commands passwords vulnerabilities interfaces users scripts accounts powerful functional powerful reasons platforms applications situations technology violence servers permissions source code programs Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MariaDB MySQL Shulou Technology NVidia Shulou Information