HackTheBox: Builder
Enumeration 1 export target=10.129.230.220 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,8080 -T5 $target Web Application (8080) Jenkins 2.441 There is a user, jennifer On Jenkins 2.441 there is a arbitrary file read vulnerability, CVE-2024-23897, and there is a public exploit for it: https://github.com/godylockz/CVE-2024-23897 We can get the var/jenkins_home/users/users.xml There is a user directory jennifer_12108429903186576833, letβs read its config file ...