Jenkins unauthorized access-arbitrary command execution
Unauthorized access to jenkins-introduction to 0x00 jenkins for arbitrary command execution
Enkins is a powerful application that allows continuous integration and continuous delivery of projects, regardless of platform. This is a free source code that can handle any type of build or continuous integration. Integrated Jenkins can be used for some testing and deployment technologies. Jenkins is a piece of software that allows continuous integration.
Reasons for 0x01 vulnerabilities
Jenkins does not set the account password, or uses a weak account password
Recurrence of 0x02 vulnerabilities
By default, users in the Jenkins panel can choose to execute script interface to operate some system-level commands. Users can obtain server permissions through unauthorized access vulnerabilities or brute force cracking of user passwords into the script execution interface.
Any command execution interface:
Http://ip:port/script
Println "ifconfig". Execute (). Text