mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
Add CVE-2018-1000861
This commit is contained in:
parent
bff02bf459
commit
d7ebd503f0
11
Jenkins/CVE-2018-1000861/README.md
Normal file
11
Jenkins/CVE-2018-1000861/README.md
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
# CVE-2018-1000861 Jenkins Remote Code Execution Vulnerability
|
||||||
|
|
||||||
|
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
|
||||||
|
|
||||||
|
Affected version: 2.153 and earlier, LTS 2.138.3 and earlier
|
||||||
|
|
||||||
|
FOFA query rule: app="Jenkins"
|
||||||
|
|
||||||
|
# Demo
|
||||||
|
|
||||||
|

|
BIN
Jenkins/CVE-2018-1000861/jenkins_CVE-2018-1000861.gif
Normal file
BIN
Jenkins/CVE-2018-1000861/jenkins_CVE-2018-1000861.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 5.6 MiB |
Loading…
x
Reference in New Issue
Block a user