mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
Add CVE-2017-1000353
This commit is contained in:
parent
d15ede94b8
commit
9a4ef56505
10
Jenkins/CVE-2017-1000353/README.md
Normal file
10
Jenkins/CVE-2017-1000353/README.md
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
# CVE-2018-1000353 Jenkins Remote Code Execution Vulnerability
|
||||||
|
|
||||||
|
An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blacklist-based protection mechanism.
|
||||||
|
|
||||||
|
**[FOFA](https://fofa.so/result?qbase64=YXBwPSJKZW5raW5zIg%3D%3D) query rule**: app="Jenkins"
|
||||||
|
|
||||||
|
# Demo
|
||||||
|
|
||||||
|

|
||||||
|
|
BIN
Jenkins/CVE-2017-1000353/jenkins_CVE-2018-1000353.gif
Normal file
BIN
Jenkins/CVE-2017-1000353/jenkins_CVE-2018-1000353.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 1.4 MiB |
Loading…
x
Reference in New Issue
Block a user