Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2016-9299 PoC — CloudBees Jenkins 安全漏洞

Source
Associated Vulnerability
Title:CloudBees Jenkins 安全漏洞 (CVE-2016-9299)
Description:CloudBees Jenkins(前称Hudson Labs)是美国CloudBees公司的一套基于Java开发的持续集成工具,它主要用于监控持续的软件版本发布/测试项目和一些定时执行的任务。LTS(Long-Term Support)是CloudBees Jenkins的一个长期支持版本。remoting是其中的一个远程管理模块。 CloudBees Jenkins 2.32之前的版本和LTS 2.19.3之前的版本中的远程模块存在安全漏洞。攻击者可借助特制的序列化Java对象利用该漏洞执行任意代码。
Description
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
File Snapshot

id: CVE-2016-9299 info: name: Jenkins CLI - HTTP Java Deserialization author: iamnoooob,rootxha ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.