CVE-2025-59474: Jenkins Sidepanel – Unauthorized Agent/Queue Exposure

CVE-2025-59474: Jenkins Sidepanel - Unauthorized Agent/Queue Exposure-渗透云记 - 专注于网络安全与技术分享
CVE-2025-59474: Jenkins Sidepanel – Unauthorized Agent/Queue Exposure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-59474: jenkins Sidepanel – Unauthorized Agent/Queue Exposure

漏洞描述

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享