Jenkins 2.138 with the Script Security and Pipeline plugins, vulnerable to CVE-2018-1000861: the Stapler web framework lets an anonymous user reach methods that compile a Groovy pipeline script, and an annotation in it runs code at compile time.
Pas commencéDockercommit f20ab63x86_64 · aarch64Secret
Exploit CVE-2018-1000861 to run a command on the Jenkins server without logging in.
Le brief de ce lab se trouve dans son dépôt.