4 ms·
TL;DR: Looks like there was a server with an unpatched Jenkins instance running, which allowed RCE. [0] Someone (presumably a developer) was connected to that
by odensc 8y ago
TL;DR: Looks like there was a server with an unpatched Jenkins instance running, which allowed RCE. [0]
Someone (presumably a developer) was connected to that compromised server via SSH, and had forwarded their SSH agent to it. [1]
Apparently that person had root access to the production servers, allowing the attacker to login via the forwarded agent. Yikes.
[0]: https://matrix.org/blog/2019/04/11/security-incident/ https://matrix.org/blog/2019/04/11/security-incident/
[1]: https://github.com/matrix-org/matrix.org/issues/358 https://github.com/matrix-org/matrix.org/issues/358
- lucb1e 8y agoThanks for that summary, the twitter thread that I read on it was not quite as enlightening as this small summary!