Security flaws in 100+ Jenkins plugins put enterprise networks at risk

A security researcher has found and reported security flaws in more than 100 different Jenkins plugins over the last 18 months, and despite efforts to notify developers, many of these plugins have not received a fix. See also 10 dangerous app vulnerabilities to watch out for (free PDF) The Jenkins team has issued ten security advisories about these vulnerabilities in the last 18 months, warning developers to uninstall vulnerable extensions [1, 2, 3, 4, 5, 6, 7, 8, 9, 10].

Read full article on ZDNet