H3-2020-0021
Unauthenticated Access to the Jenkins Script Console
Category | SECURITY_MISCONFIGURATION |
Base Score | 9.1 |
Description
The Jenkins server exposes the script console to unauthenticated users.
Impact
Attackers can use the Jenkins script console to execute arbitrary commands on the Jenkins host and to gain shell access. Attackers can gain access to credentials stored in Jenkins or other confidential data.