jenkins exploits
jenkins exploits
Deserialization RCE in old Jenkins (CVE-2015-8103, Jenkins 1.638 and older)
Authentication/ACL bypass (CVE-2018-1000861, Jenkins <2.150.1)
Metaprogramming RCE in Jenkins Plugins (CVE-2019-1003000, CVE-2019-1003001, CVE-2019-1003002)
CheckScript RCE in Jenkins (CVE-2019-1003029, CVE-2019-1003030)
Git plugin (<3.12.0) RCE in Jenkins (CVE-2019-10392)
Dumping builds to find cleartext secrets
Password spraying
Decrypt Jenkins secrets offline
Additional Reading
Last updated