RCE via exposed JMX server on jabber.37signals.com/jabber.basecamp.com
Low
B
Basecamp
Submitted None
Team Summary
Official summary from Basecamp
@ian reported that `jabber.37signals.com` and `jabber.basecamp.com` exposed on port `555` an unauthenticated Java JMX server which was vulnerable to RCE. We've looked into this and found that we forgot to clean up some DNS records when we decomissioned Jabber so the exposed IP address were not part of our infrastructure. We've removed the old DNS entries for `jabber.basecamp.com` / `jabber.37signals.com`.
Actions:
Reported by
ian
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$100.00
Submitted
Weakness
Deserialization of Untrusted Data