4 ms·
I receive vulnerability notifications for Jenkins, pretty much regularly... mostly XSS and RCE. https://www.cvedetails.com/vulnerability-list/vendor_id-15865/p
by tinix 7y ago
I receive vulnerability notifications for Jenkins, pretty much regularly... mostly XSS and RCE.
https://www.cvedetails.com/vulnerability-list/vendor_id-15865/product_id-34004/Jenkins-Jenkins.html https://www.cvedetails.com/vulnerability-list/vendor_id-1586...
I'm just waiting for Apache to adopt it, and then it'll sit and fester like everything else in the Apache graveyard, full of vulnerabilities and slowly decaying.
Those are just Jenkins core exploits too... there are so many many more for Jenkins plugins.... https://www.cvedetails.com/vulnerability-list/vendor_id-15865/Jenkins.html https://www.cvedetails.com/vulnerability-list/vendor_id-1586...
- mfer 7y agoJenkins is now part of the CD Foundation (https://cd.foundation/ https://cd.foundation/) which is one of the linux foundation sub-foundations. Don't expect it to show up in the apache foundation.
- 1ris 7y agoI don't think tinix was excpeting it to literally become a apache project - he was just saying its in a state of decay that apache is infamous for.
- VectorLock 7y agoLast place I was at had their unmanaged Jenkins servers get compromised and used to run crypto miners.
- jennbriden 7y agoWere they using an older version of Jenkins on the public internet? There's been a randomized GUID applied to the initial Jenkins admin password, which you can only access if you have direct access to the Jenkins install. I think this was added in 2016.
- VectorLock 7y agoIt was an older version with a vulnerability but as far as I know not a default password.
- deleted 7y ago[deleted]