Skip to content

Build1 publisher2 min readPublished

Jenkins accounts for 1,538 of 1,739 build-chain hosts a September scan found on the open internet

ZoomEye queries on 22 September 2026 found 1,538 Jenkins, 169 Harbor and 32 SonarQube instances reachable from the internet. These tools hold deploy credentials by design, so every reachable instance is a possible route into production.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Jenkins accounts for 1,538 of 1,739 build-chain hosts a September scan found on the open internet
Generated illustration

What happened

  • According to the post, a reachable Jenkins web UI can expose job names, build logs and, in some configurations, the script console.
  • A reachable Harbor registry with weak credentials lets an attacker pull private images that reveal application internals, embedded secrets and deployment topology, the post says.
  • Harbor and SonarQube have both shipped default credentials on first install, and the post calls an exposed SonarQube on defaults a configuration issue that needs no exploit.
  • Portainer and Grafana, queried for comparison, came back two orders of magnitude larger, showing the index covers these products and the build-chain counts are small in their own right.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Because a CI server's outbound access to production sets the blast radius, egress from the controller needs controlling alongside authentication.
  • cost SonarQube has the fewest hosts but the most to lose per host: one instance can hold the source of every project plus findings that describe exploitable weaknesses.
  • decision The 1,538 total cannot tell a team whether its own controller is in it. The post's first check is a product-name query against the team's own netblocks.

The counts measure reachability. The post names the two settings that turn reachability into disclosure: anonymous read on Jenkins and public project visibility on SonarQube [14]. The query results do not say how many of the 1,538 Jenkins hosts have anonymous read enabled. That makes 1,538 the upper limit on controllers that show anything to someone without a login [3].

For that number to become a count of routes into production, each fingerprint match has to be a live controller. It also has to hold the write tokens, push credentials and cloud keys the post lists [4]. ZoomEye app: queries identify the product, not just the port. They still depend on the product's fingerprint, and the post calls its figures a snapshot [2]. The post explains the exposure as tooling "stood up quickly for a project and never moved behind the perimeter" [21].

Where a match is live, the post's framing holds. "Compromising a CI server is not a step toward production access; it is production access," the author wrote [5]. I would put the most weight on the build log, which the post calls an underrated disclosure. Logs frequently contain environment variables, tokens echoed by a build step and internal hostnames [7]. The post says logs that contain tokens should be treated as secrets, and that retention should be checked with that in mind [16].

Harbor's push side is the bigger risk. An attacker with push access to the registry a cluster takes its images from can get into the supply chain without first compromising the build system [10]. The post's control for that is good engineering. Image signing with admission enforcement turns a push into a blocked deployment [11]. It has one dependency. Signing keys for artefacts are on the post's own list of what a CI server holds [4]. Signing stops an attacker who has only the registry. It does not stop one who holds the Jenkins controller, if the keys live there.

Jenkins is about 88 percent of the 1,739 build-chain results [19][20]. For Jenkins, the post's controls are network placement and authentication. That means a VPN or access proxy in front, and anonymous read disabled unless there is a specific reason to allow it [8].

What to watch

  • A rerun of the same ZoomEye queries, to test whether 1,538 Jenkins hosts is a stable baseline or a one-day fingerprint snapshot.
  • Any measurement of how many reachable Jenkins hosts allow anonymous read, the figure that would turn this reachability count into a disclosure count.
  • New Jenkins plugin advisories, since the post places most past Jenkins vulnerabilities in the plugin ecosystem.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories