ZoomEye finds 1,537 internet-exposed Jenkins controllers
ZoomEye scanning data shows 1,537 Jenkins controllers reachable from the public internet. That exposure leaves them open to future flaws like CVE-2024-23897, which allowed unauthenticated file reads on the controller.
- ZoomEye reported 1,537 internet-reachable Jenkins instances
- CVE-2024-23897 allowed unauthenticated file reads via the CLI
- Exposure persists because controllers sit outside security inventories
- Defenders are urged to put controllers behind VPNs and track plugins
Read next
Security