As a red teamer, you encountered a Jenkins instance that is vulnerable to CVE-2024-23897, which allowed for limited arbitrary file read. Without credentials and with the /script endpoint inaccessible, you sought to leverage this vulnerability by revealing Hudson to decypt the credentials.
DOCUMENTS Jenkins (CVE-2024-23897)
by n3od4y - 07-08-24, 10:50 AM
« Next Oldest | Next Newest »
|
Users browsing this thread: 2 Guest(s)