Closed Bug 1334721 Opened 8 years ago Closed 8 years ago

Outdated Jenkins Ver 1.595 Instance Situated on - http://qa.stage.mozaws.net:8080/

Categories

(Websites :: Other, defect)

Staging
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: griffin.francis.1993, Assigned: rpapa)

Details

(Keywords: sec-high, wsec-other)

User Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36 Steps to reproduce: Situated at - http://qa.stage.mozaws.net:8080/ (WHOIS Information Indicates that this is a Mozilla owned domain) Jenkins version 1.595 was released on 2014/12/21. Since then Multiple Remote Code Execution Vulnerabilities have been released for this platform. I believe that this Jenkins instance may have been forgotten about by Mozilla as other instances are running the latest version. Registration on this Instance also appears to be enabled by default. Actual results: Jenkins Instance is outdated and may be vulnerable to Remote Code Execution vulnerabilities. Expected results: This instance should either be decommissioned or updated to the latest version.
Assignee: nobody → rpappalardo
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(rpappalardo)
Version: unspecified → Staging
Keywords: sec-high, wsec-other
Thanks for the triage on this report Greg. Much appreciated.
It should also be noted that the instance allows sign up (with no perms), not sure why that is, and that it's not requiring HTTPS. Recommend that we pull it private or follow best practices with this host if it's going to stay public.
Flags: needinfo?(rpappalardo)
this server was setup by QA mgr who is no longer w/ mozilla. we no longer need this server so I will decomission.
i've decommissioned the host
Status: ASSIGNED → RESOLVED
Closed: 8 years ago
Resolution: --- → FIXED
Confirmed as fixed. Thanks for the quick turn around time on this report like usual.
Group: websites-security
You need to log in before you can comment on or make changes to this bug.