Skip to content
← LibraryTechnique entry
CI-PIPELINE-RCEExecution

Jenkins Script Console RCE

Jenkins /script Groovy console reachable unauth or with weak creds — Groovy exec() = RCE as Jenkins master.

§ Where this technique fits

CI-PIPELINE-RCE is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 1×