QID 730244
Date Published: 2021-11-02
QID 730244: Jenkins Script Console Remote Code Execution (RCE) Detected
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
Jenkins Script Console allows users to execute any system command with Groovy/Java Scripts. Though this is a feature and not a vulnerability, the script console shouldn't be accessible without authentication.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of jenkins
If an attacker is able to access the Jenkins Script Console, it can lead to code execution including getting a shell on the system
Solution
Customer are advised that the Jenkins Script Console must not be accessible without authentication
For an example of the vulnerability please refer here
For an example of the vulnerability please refer here
Vendor References
CVEs related to QID 730244
Software Advisories
| Advisory ID | Software | Component | Link |
|---|