Tag

Sonarsource

All articles tagged with #sonarsource

"Urgent Patch Released for Critical Jenkins RCE Vulnerability"

Originally Published 1 year ago — by BleepingComputer

Featured image for "Urgent Patch Released for Critical Jenkins RCE Vulnerability"
Source: BleepingComputer

Multiple proof-of-concept exploits have been released for a critical Jenkins vulnerability, allowing unauthenticated attackers to read arbitrary files and execute arbitrary CLI commands. SonarSource researchers discovered two flaws, one enabling data access and the other allowing arbitrary command execution. Jenkins has released fixes for the flaws, but researchers have already reproduced attack scenarios and created working PoC exploits, with reports of hackers actively exploiting the vulnerabilities in the wild.