id: jenkins-detect info: name: Jenkins Detection author: philippdelteil,daffainfo,c-sh0,AdamCrosser severity: info reference: - https://www.jenkins.io/doc/book/using/remote-access-api/#RemoteaccessAPI-DetectingJenkinsversion - https://github.com/jenkinsci/jenkins/pull/470 - https://www.jenkins.io/doc/book/security/access-control/permissions/#access-granted-without-overallread classification: cpe: cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* metadata: max-request: 2 vendor: jenkins product: jenkins shodan-query: http.favicon.hash:81586312 category: devops tags: tech,jenkins,detect http: - method: GET path: - "{{BaseURL}}" - "{{BaseURL}}/whoAmI/" host-redirects: true max-redirects: 2 stop-at-first-match: true matchers-condition: and matchers: - type: word part: header words: - "x-jenkins:" case-insensitive: true - type: word words: - "Jenkins" extractors: - type: kval name: version kval: - x_jenkins - type: kval kval: - version # digest: 4a0a00473045022003514a46c47a8f73f88d42fb0a4e926f061dd40fe52f73d4c00d633f502390460221008cd44f6ac8838884dc8fada8490ef3c3dfa9b36b9efb55e650fe19a4d083bfa6:922c64590222798bb761d5b6d8e72950