Playing with Jenkins File Read [CVE-2024-23897]

Поділитися
Вставка
  • Опубліковано 21 гру 2024

КОМЕНТАРІ • 16

  • @deamer44
    @deamer44 9 місяців тому

    Good explanation! I like how you actually tried to understand what was going on instead of skirting over a bunch of stuff like other youtubers do!

  • @furttech
    @furttech 10 місяців тому

    Interesting approach to this vuln, nice video showcasing. Thx.

  • @BlackwinghacksBlogspot
    @BlackwinghacksBlogspot 10 місяців тому

    Thanks for the explanation. All the best with understanding the bash xD

  • @mateuszgierblinski
    @mateuszgierblinski 10 місяців тому

    Great vid. Thank. you, 0xdf!

  • @youshouldsee8240
    @youshouldsee8240 10 місяців тому

    Great explanation Thanks for sharing

  • @ВиталийОвчаренко-и1н
    @ВиталийОвчаренко-и1н 8 місяців тому

    To resolve the issue with stages in Jenkins related to the CVE-2024-23897 (Arbitrary File Read Vulnerability), you should update Jenkins to version 2.441 or later, or LTS 2.426.3 or later. This update disables a feature of the CLI command parser that allows unauthenticated attackers to read arbitrary files on the Jenkins controller file system. Additionally, you can follow the security advisory provided by Jenkins to ensure your system is secure and protected against this vulnerability.

  • @MohabMohab-zr7md
    @MohabMohab-zr7md 4 місяці тому

    It would be nice if you can put that bash file on a github repo!

  • @kodeish
    @kodeish 4 місяці тому

    What if the target server is Windows? What file do we need to search to obtain sensitive information?

    • @0xdf
      @0xdf  4 місяці тому

      would have to look in more detail into what jenkins stores where on windows. would probably be worth spinning up a Windows VM and installing jenkins to check it out.

    • @kodeish
      @kodeish 4 місяці тому

      @@0xdf I really search well but I didn't found any CVE or github report for windows. Yeah I should try installing jenkins on VM, thanks

  • @alelewi-y3y
    @alelewi-y3y 10 місяців тому

    Thanx man

  • @MAX-nv6yj
    @MAX-nv6yj 9 місяців тому

    Nice video, but I have no clue about the bash loop 😂😅.
    But great approach❤.

  • @markusk.9850
    @markusk.9850 10 місяців тому

    Fiddled about with it and noticed that, if I set up the commands on a different file descriptor (i. e. 3) then the while read (-u 3) loop runs just fine.
    Haven't looked at the source for the cli yet, but maybe it somehow messes with stdin?

  • @netbin
    @netbin 10 місяців тому

    howdy hoaxbeef