Featured
Published on February 14th, 2023 📆 | 8228 Views ⚑
0Jenkins – SECURITY-200 / CVE-2015-5323 PoC Carnal0wnage
API tokens of other users available to admins
SECURITY-200 / CVE-2015-5323
API tokens of other users were exposed to admins by default. On instances that don’t implicitly grant RunScripts permission to admins, this allowed admins to run scripts with another user’s credentials.
Affected versions
All Jenkins main line releases up to and including 1.637
All Jenkins LTS releases up to and including 1.625.1
PoC
Tested against Jenkins 1.6.37
From the script console:
Gloss