CVE-2016-9299
CRITICAL EXPLOITED NUCLEIJenkins < 2.32 and LTS < 2.19.3 - Remote Code Execution via LDAP Query Injection
Title source: llmExploitation Summary
CVE-2016-9299 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 3 public exploits from researchers including Metasploit, r00t4dm, Matthias Kaiser, Alisa Esage, Ivan, YSOSerial, including a Metasploit module exploits/linux/misc/jenkins_ldap_deserialize.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits CVE-2016-9299, a Java deserialization vulnerability in Jenkins, allowing unauthenticated remote code execution via crafted HTTP requests. It uses YSOSerial payloads for exploitation.
Description
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
Exploits (3)
This Metasploit module exploits CVE-2016-9299, a Java deserialization vulnerability in Jenkins, allowing unauthenticated remote code execution via crafted HTTP requests. It uses YSOSerial payloads for exploitation.
The repository contains no actual exploit code for CVE-2016-9299, only JavaScript bundles and scripts unrelated to the vulnerability. The README is empty, and there is no technical analysis or PoC provided.
This Metasploit module exploits a Java deserialization vulnerability in Jenkins (CVE-2016-9299) to achieve remote code execution. It uses a crafted LDAP server to deliver a malicious serialized payload, bypassing authentication.
Nuclei Templates (1)
product:"jenkins"
icon_hash=81586312
References (10)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H