Jenkins 2.441, vulnerable to CVE-2024-23897: the CLI's args4j parser replaces an argument starting with @ by the content of that file, so anyone reaching the CLI reads files from the controller, up to secrets that lead to code execution.
Pas commencéDockercommit cc03a09x86_64 · aarch64Secret
Exploit CVE-2024-23897 to read files on the Jenkins controller and get a shell.
Le brief de ce lab se trouve dans son dépôt.