Unauthenticated Jenkins instance exposed information related to █████

Disclosed: 2024-01-26 18:55:52 By ashutosh7 To deptofdefense
High
Vulnerability Details
Affected URLs - ██████████blue/organizations/jenkins/pipelines ████████ ██████████ ████ Also notice that the information is transmitted in clear text as the server is running on HTTP. ## Impact An attacker can read or edit sensitive information belonging to █████ by abusing this vulnerability. ## System Host(s) ███████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Navigate to ███████ , and other sections. It is exposing information related to ███ ## Suggested Mitigation/Remediation Actions It is recommended to Implement authentication on this Jenkins instance
Actions
View on HackerOne
Report Stats
  • Report ID: 2178941
  • State: Closed
  • Substate: resolved
  • Upvotes: 35
Share this report