JENKINS
Jenkins
#Few links to Dive deep
https://hackerone.com/reports/768266
https://hackerone.com/reports/182104
https://portswigger.net/daily-swig/jenkins-security-unpatched-xss-csrf-bugs-included-in-latest-plugin-advisory
https://logicbomb.medium.com/bugbounty-from-finding-jenkins-instance-to-command-execution-secure-your-jenkins-instance-9bd1e75c2288
https://medium.com/@kerstan/jenkins-arbitrary-file-reading-vulnerability-cve-2024-23897-bug-bounty-tuesday-8e3a69443d9b
https://nordicdefender.com/blog/critical-jenkins-vulnerability-cve-2024-23897
https://medium.com/@Cyfirma_/jenkins-cve-2024-23897-vulnerability-analysis-and-exploitation-17b3adc6881a
https://syedabeerahmed.medium.com/rce-jenkins-cve-2024-23897-6f56ac3ecf5d
https://medium.com/@elniak/critical-jenkins-rce-vulnerability-cve-2024-23897-402061a2b187
https://medium.com/@maheshwar.ramkrushna/enabling-csrf-protection-in-jenkins-step-by-step-guide-and-advantages-d8737d503889
https://medium.com/@red_darkin/how-to-replicate-jenkins-cve-2024-23897-arbitrary-file-read-vulnerability-260c8174dd94
#10 Most Common things to check
Open Jenkins Instances
Weak Authentication and Authorization
Outdated Jenkins Core or Plugins
Script Security Issues
Insufficient Plugin Security
Exposed Credentials
Jenkins File Leaks
Cross-Site Request Forgery (CSRF)
Build Process Manipulation
Exposed Jenkins API
Check Youtube for more.....
Last updated