May 2020
Intermediate to advanced
544 pages
12h 57m
English
After the script console exploits of Jenkins became well known, a lot of people started configuring Jenkins with anonymous read access set to disabled in the global security configuration settings:

With this setting, anonymous users could no longer see anything except the specific whitelisted items shown in the following screenshot (these were provided at the following URL: https://github.com/jenkinsci/jenkins/blob/41a13dffc612ca3b5c48ab3710500562a3b40bf7/core/src/main/java/jenkins/model/Jenkins.java#L5258):

We already know ...
Read now
Unlock full access