Loading HuntDB...

RCE via exposed JMX server on jabber.37signals.com/jabber.basecamp.com

Low
B
Basecamp
Submitted None

Team Summary

Official summary from Basecamp

@ian reported that `jabber.37signals.com` and `jabber.basecamp.com` exposed on port `555` an unauthenticated Java JMX server which was vulnerable to RCE. We've looked into this and found that we forgot to clean up some DNS records when we decomissioned Jabber so the exposed IP address were not part of our infrastructure. We've removed the old DNS entries for `jabber.basecamp.com` / `jabber.37signals.com`.

Reported by ian

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$100.00

Submitted

Weakness

Deserialization of Untrusted Data