The Register Home Page

back to article Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released

The number of public-facing installs of Jenkins servers vulnerable to a recently disclosed critical vulnerability is in the tens of thousands. Scans from internet security data company Shadowserver indicate roughly 45,000 instances of the hugely popular CI/CD automation server are vulnerable to CVE-2024-23897, the critical …

  1. Anonymous Coward
    Anonymous Coward

    Welcome to dependency hell..

    Ah the fun of an enforced Jenkins upgrade and dependency hell when your plugins start complaining.

  2. Stu J

    Why the hell...

    ...would you have a Jenkins server accessible on a public IP, rather than behind a VPN or a Zero Trust Load Balancer?

    That's like having your car keys hanging in a flimsy glass box outside your front door...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like