漏洞描述
The Jenkins allows registering a new user and accessing the dashboard.
id: jenkins-openuser-register
info:
name: Jenkins Open User registration
author: DhiyaneshDk
severity: medium
description: The Jenkins allows registering a new user and accessing the dashboard.
remediation: Its recommended to turn off user registration.
reference:
- https://www.acunetix.com/vulnerabilities/web/jenkins-open-user-registration/
classification:
cpe: cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: jenkins
product: jenkins
shodan-query: "X-Jenkins"
tags: misconfig,jenkins,apache,tomcat,vuln
http:
- method: GET
path:
- "{{BaseURL}}/signup"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Create an account! [Jenkins]"
- "Register [Jenkins]"
- "Register - Jenkins"
- type: word
part: header
words:
- "text/html"
- type: status
status:
- 200
# digest: 4a0a00473045022100d4796fa4f89a727de8b124cf9bdde231647e219aee0ecac55ec5402cc0cac75b02205d70567068aabbb0a670b96dc14e652555b1e4233c275c9c396de153e21691bc:922c64590222798bb761d5b6d8e72950