Skip to content

H3-2020-0021

Unauthenticated Access to the Jenkins Script Console

Category SECURITY_MISCONFIGURATION
Base Score 9.1

Description

The Jenkins server exposes the script console to unauthenticated users.

Impact

Attackers can use the Jenkins script console to execute arbitrary commands on the Jenkins host and to gain shell access. Attackers can gain access to credentials stored in Jenkins or other confidential data.

References