
Jenkins
External Program
Submit bugs directly to this organization
If you find a vulnerability in Jenkins, please report it in the issue tracker under the SECURITY project. This project is configured in such a way that only the reporter and the core Jenkins developers can see the details.
By restricting the access to the potential sensitive information, we can work on the problem and deliver the fix before the method of attack becomes well-known.
For information on what makes a good report in general, see: How to report an issue