devops-misconfiguration

1 article
sort: new top best
clear filter
0 6/10

A DevOps engineer discovered unauthenticated RCE as root on publicly exposed Marathon container orchestration instances by leveraging the task scheduling API to execute arbitrary commands without authentication, discovered via Shodan reconnaissance.

Marathon Mesos DC/OS Shodan netcat curl
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details