目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-28157 PoC — Jenkins GitBucket Plugin 安全漏洞

来源
关联漏洞
标题: Jenkins GitBucket Plugin 安全漏洞 (CVE-2024-28157)
Description:Jenkins和Jenkins Plugin都是Jenkins开源的产品。Jenkins是一个应用软件。一个开源自动化服务器Jenkins提供了数百个插件来支持构建,部署和自动化任何项目。Jenkins Plugin是一个应用软件。 Jenkins GitBucket Plugin 0.8 版本之前存在安全漏洞,该漏洞源于不会清理构建视图上的 Gitbucket URL,从而导致存储型跨站脚本 (XSS) 漏洞,能够被能够配置作业的攻击者利用。
Description
Proof of Concept for CVE-2024-28157
介绍
# PoC CVE-2024-28157

### Overview
Jenkins **GitBucket** Plugin veersion 0.8 and earlier does not sanitize Gitbucket
URLs on build views, resulting in a stored **cross-site scripting XSS** vulnerability
exploitable by attackers able to configure jobs.

### Exploitation Steps

#### Setup Jenkins (using docker):
1. Use docker to run the jenkins image.
```
docker run jenkins/jenkins:lts
```
2. Install the Gitbucket Plugin from the GUI (The most recent version of this plugin is 0.8 which is vulnerable so the exploit will work).

#### Exploit:
1. Go to New Item and create a new job. Select the item type (I went with freestyle project in the demo).
2. In the configurations, provide a simple xxs payload `javascript:alert('hello')` inside the Gitbucket URL section.
3. Save the configs and go to the Gitbucket option. Observe the xss execution. 

### Exploit Video
[jenkinsxxsexploit.webm](https://github.com/user-attachments/assets/fd2272e6-0d69-4ced-8ceb-531bfa2396f2)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →