Get a Pentest and security assessment of your IT network.

News

Jenkins Flaw Can Allow Attackers to Log In as Admins

New research from CyberArk finds a critical flaw in Jenkins servers that can allow an attacker to log in as an administrator. Jenkins is an open source Java server tool that has found wide use in DevOps methodology. CyberArk researchers first identified the problem — CVE-2018-1999001 — which allowed attackers to provide crafted login credentials that would cause Jenkins to move the startup configuration (config.xml) file from the Jenkins home directory. Another bug that CyberArk found is a bug that will crash the Java virtual machine due to low memory.”]

Source: https://www.darkreading.com/application-security/open-source/jenkins-flaw-can-allow-attackers-to-log-in-as-admins/a/d-id/748385

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks