Shodan + Jenkins to get RCEs on Servers

Good read and thanks for sharing my report! ( But you don’t even need to install the terminal plugin to have RCE.

If you’re comfortable with Groovy (, you can use the built in Groovy script console (Manage Jenkins > Script Console > “whoami”.execute().text is a slightly less intrusive PoC.

