Jenkins CLI RMI Java Deserialization

Discussion in 'News Aggregator' started by Packet Storm, 15 Dec 2015.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a vulnerability in Jenkins. An unsafe deserialization bug exists on the Jenkins master, which allows remote arbitrary code execution. Authentication is not required to exploit this vulnerability.

    Continue reading...
     

Share This Page

Loading...