Unauthenticated Jenkins instance exposed information related to █████
High
Vulnerability Details
Affected URLs - ██████████blue/organizations/jenkins/pipelines
████████
██████████
████
Also notice that the information is transmitted in clear text as the server is running on HTTP.
## Impact
An attacker can read or edit sensitive information belonging to █████ by abusing this vulnerability.
## System Host(s)
███████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Navigate to ███████ , and other sections. It is exposing information related to ███
## Suggested Mitigation/Remediation Actions
It is recommended to Implement authentication on this Jenkins instance
Actions
View on HackerOneReport Stats
- Report ID: 2178941
- State: Closed
- Substate: resolved
- Upvotes: 35