Featured Jenkins - SECURITY-200 / CVE-2015-5323 PoC Carnal0wnage

Published on February 14th, 2023 📆 | 8228 Views ⚑

0

Jenkins – SECURITY-200 / CVE-2015-5323 PoC Carnal0wnage


Powered by iSpeech

API tokens of other users available to admins



SECURITY-200 / CVE-2015-5323



API tokens of other users were exposed to admins by default. On instances that don’t implicitly grant RunScripts permission to admins, this allowed admins to run scripts with another user’s credentials.





Affected versions

All Jenkins main line releases up to and including 1.637



All Jenkins LTS releases up to and including 1.625.1







PoC

Tested against Jenkins 1.6.37





From the script console:

run some groovy code to get the token of another user
wrong token
correct token

Source link

Tagged with:



Comments are closed.