FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

java-deserialization-exploits/Jenkins at master · exploit-inters/java-deserialization-exploits · GitHub

Repository navigation

Latest commit

 

History

History
 
 

Folders and files

README.md

Jenkins CLI RMI Java Deserialization RCE (CVE-2015-8103)

Exploit for the Jenkins CLI RMI Java Deserialization RCE (CVE-2015-8103)

The python script uses ysoserial to dynamically generate the payload. Therefore java is required as well.

Jenkins Groovy XML RCE (CVE-2016-0792)

Exploit for Jenkins Groovy XML RCE (CVE-2016-0792)

Note: Although this is listed as a pre-auth RCE, during my testing it only worked if authentication was disabled in Jenkins


Back | FazBrowse Home | New Git URL