""ET WEB_SPECIFIC_APPS Jenkins RCE CVE-2019-1003000""

SID: 2027346

Revision: 2

Class Type: web-application-attack

Metadata: attack_target Server, created_at 2019_05_10, cve CVE_2019_100300, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2019_05_10

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HTTP_SERVERS

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST" Depth: 4

  • Value: "config.xml"

  • Value: "|3c|script|3e 0a|"

  • Value: "import|20|org|2e|buildobjects|2e|process|2e|ProcBuilder"

  • Value: "|40|Grab|28 27|org|2e|buildobjects|3a|jproc|3a|"

  • Value: "|27 29 0a|"

  • Value: "print|20|new|20|ProcBuilder|28 22 2f|"

  • Value: "|22 29 2e|run|28 29|"

  • Value: "|2e|getOutputString|28|"

  • Value: "|3c 2f|script|3e|"

Within: 30

PCRE:

Special Options:

  • http_method

  • http_uri

  • http_client_body

  • http_client_body

  • fast_pattern

  • http_client_body

  • http_client_body

  • http_client_body

  • http_client_body

  • http_client_body

  • http_client_body

source