Jenkins CVE-2024-23897
Analysis and proof-of-concept (PoC) for Jenkins file-read vulnerability CVE-2024-23897.
rektsu
has sudo privileges over a binary, and misconfigurations in shared library objects can be exploited to gain root privileges.
puma
. Next, user puma has sudo privileges for systemctl
, and the less
pager is exploited to escalate privileges.
pg_write_server_files
privileges, enabling me to write files on the system as the user postgres. Exploiting a cron job that interactively logs in as postgres, I utilized the write privileges to execute commands in the context of postgres. Further enumeration revealed multiple root TTY sessions, providing an opportunity to hijack them and execute commands as the root user.