Jenkins
Jenkins exploitation
Discovery/Footprinting
Open Registration
/signup
/jenkins/signupEnumeration


Admin access - Script Console
Linux

Windows
Reverse Shell
Linux
Metasploit
Windows
Retrieve AWS credentials
No admin access but could add or edit build steps




CVE-2025-53652 - Command Injection via Git Parameter
CVE-2024-23897 - Arbitrary File Read Vulnerability Leading to RCE
CVE-2024-43044 - Arbitrary file read that allows an agent to fetch files from the controller
Resources
Interesting Books
Interesting BooksLast updated
