CVE-2016-9299 code execution vulnerability

From PwnWiki
Revision as of 10:43, 10 June 2021 by Pwnwiki (talk | contribs) (Created page with "==Introduction== The remote processing module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code through elaborate serialization of...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Bahasa Indonesia • ‎Chinese • ‎English • ‎中文(中国大陆)‎ • ‎中文(简体)‎ • ‎粵語

Introduction

The remote processing module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code through elaborate serialization of Java objects, thereby triggering LDAP queries to third-party servers.

MSF

exploit/linux/misc/jenkins_ldap_deserialize