Jenkins CLI RMI Java Deserialization
Posted by deepcore on December 15, 2015 – 9:17 pm
This Metasploit module exploits a vulnerability in Jenkins. An unsafe deserialization bug exists on the Jenkins master, which allows remote arbitrary code execution. Authentication is not required to exploit this vulnerability.
Post a reply
You must be logged in to post a comment.