Unauthenticated Jenkins instance exposed information related to █████
High
U
U.S. Dept Of Defense
Submitted None
Actions:
Reported by
ashutosh7
Vulnerability Details
Technical details and impact analysis
Affected URLs - ██████████blue/organizations/jenkins/pipelines
████████
██████████
████
Also notice that the information is transmitted in clear text as the server is running on HTTP.
## Impact
An attacker can read or edit sensitive information belonging to █████ by abusing this vulnerability.
## System Host(s)
███████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Navigate to ███████ , and other sections. It is exposing information related to ███
## Suggested Mitigation/Remediation Actions
It is recommended to Implement authentication on this Jenkins instance
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic