5 ms·
I'm from the Jenkins project. I wish the authors of this post gave us a heads up beforehand. It put our users at unnecessary risk. At Jenkins project, We've p
by kohsuke 11y ago
I'm from the Jenkins project.
I wish the authors of this post gave us a heads up beforehand. It put our users at unnecessary risk.
At Jenkins project, We've published a mitigation script (https://jenkins-ci.org/content/mitigating-unauthenticated-remote-code-execution-0-day-jenkins-cli https://jenkins-ci.org/content/mitigating-unauthenticated-re...) while we work out a better fix for users.
- paulddraper 11y agoGeez. That sucks. I guess they really wanted those minutes of fame.
- wglb 11y agoIt seems that users have already been at unnecessary risk, given In fact, even though proof of concept code was released OVER 9 MONTHS AGO, none of the products mentioned in the title of this post have been patched, along with many more.
- needusername 11y agoHas anybody reported anything? The commons project seems to have been made aware of this just this weekend through third parties. If nobody reported anything no wonder it didn't get fixed.
- wglb 11y agoSee the talk given in January http://frohoff.github.io/appseccali-marshalling-pickles/ http://frohoff.github.io/appseccali-marshalling-pickles/