CVE-2016-9299 代碼執行漏洞

From PwnWiki
This page is a translated version of the page CVE-2016-9299 代碼執行漏洞 and the translation is 100% complete.
Other languages:

簡介

2.32之前嘅Jenkins同2.19.3之前嘅LTS中嘅遠程處理模塊允許遠程攻擊者通過精心製作嘅序列化Java對象執行任意代碼,從而觸發對第三方服務器嘅LDAP查詢。

MSF

exploit/linux/misc/jenkins_ldap_deserialize