This script is Copyright (C) 2013-2016 Tenable Network Security, Inc.
The remote web server hosts a job scheduling / management system that
is accessible without authentication.
The remote web server hosts Jenkins, a job scheduling / management
system and a drop-in replacement for Hudson. By allowing
unauthenticated access to the application, anyone may be able to
configure Jenkins and jobs, and perform builds.
Additionally, this script checks for unauthenticated access to
'/scripts' as anyone with access to the script console can run arbitrary
Groovy scripts on the remote host.
See also :
Refer to the Jenkins security guide for information on restricting
access to Jenkins.
Risk factor :
High / CVSS Base Score : 7.5
CVSS Temporal Score : 7.5
Get Nessus Professional to scan unlimited IPs, run compliance checks & moreBuy Nessus Professional Now