Top 10 winner
Hacking Jenkins Part 2 - Abusing Meta Programming for Unauthenticated RCE!
Jenkins validated pipeline scripts by handing them to the Groovy parser, but Groovy compile-time meta-programming executes code while parsing. An unauthenticated attacker uses @GrabResolver and @Grab so Grape fetches a JAR from their own server whose service Runner runs on load, giving remote code execution the script-security sandbox never sees.
Record
- Researcher
- Orange Tsai
- Published by
- Orange Tsai
- Date
- Topic
- Server
In the archive
Related sources
- Part 1: Dynamic Routing
- Traditional Chinese article
- Author exploit code
- Independent sandbox PoC
- Hacking Jenkins slides
Tags
This page is the archive's own catalogue record. The research is the work of Orange Tsai, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .