Jenkins amplification

Töma Gavrichenkov ximaera at gmail.com
Mon Feb 3 15:42:03 UTC 2020


FYI

https://nvd.nist.gov/vuln/detail/CVE-2020-2100
A nice description: https://mobile.twitter.com/Foone/status/1223063275996213248

May you live in interesting times.

Do not postpone a software update if Jenkins is deployed somewhere in
your network.

--
Töma



More information about the NANOG mailing list