Get a Pentest and security assessment of your IT network.

News

Expert found hundred of vulnerable Jenkins Plugins

A security researcher discovered vulnerabilities in more than 100 plugins of the Jenkins open source software development automation server. Most of the issues are password storage in plain text, and cross-site request forgery (CSRF) issues with missing permission checks that could be exploited by attackers steal credentials. Some of the vulnerable Jenkins plugins have been developed by third-party developers to access a wide range of services, including Twitter, AWS, and Azure. Jenkins developers have released security advisories for unpatched vulnerabilities.”]

Source: https://securityaffairs.co/wordpress/84910/hacking/jenkins-plugins-flaws.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2