Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Jenkins also routinely has massive security holes.

Last major exploit I heard about - the matrix.org exploit, was from privilege escalation through a Jenkins vulnerability [1]

[1] https://www.zdnet.com/article/matrix-hack-forces-servers-off...

--

This isn't nec a knock against Jenkins itself, but certainly a knock against thousands of orgs running their own unpatched Jenkins servers, often on the same machine as their other apps



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: