Skip to content
Jenkins
Dashboard
Manage Jenkins
Configure Global Security
Configure Global Security
LOADING
Authentication
Disable remember me
Loading...
Security Realm
Delegate to servlet container
Jenkins’ own user database
Unix user/group database
None
Authorization
Anyone can do anything
Legacy mode
Logged-in users can do anything
?
Loading...
Markup Formatter
Markup Formatter
Plain text
Treats all input as plain text. HTML unsafe characters like < and & are escaped to their respective character entities.
Agents
TCP port for inbound agents
?
Fixed
Random
Disable
Loading...
Agent protocols
Inbound TCP Agent Protocol/4 (TLS encryption)
A TLS secured connection between the controller and the agent performed by TLS upgrade of the socket.
CSRF Protection
Crumb Issuer
Default Crumb Issuer
Enable proxy compatibility
?
Loading...
Hidden security warnings
This section allows you to suppress warnings, applicable to your Jenkins configuration, provided by the updates sites. If you do, they won’t be shown by the Update Site Warnings administrative monitor. Checked warnings are reported (the default), unchecked warnings are hidden.
Security warnings
?
Jenkins core: Multiple security vulnerabilities in Jenkins 2.527 and earlier, LTS 2.516.2 and earlier
https://www.jenkins.io/security/advisory/2025-09-17/
Jakarta Mail API: SMTP command injection vulnerability
https://www.jenkins.io/security/advisory/2025-09-03/#SECURITY-3617
Jenkins core: Terrapin SSH vulnerability in Jenkins CLI client
https://www.jenkins.io/security/advisory/2024-04-17/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.550 and earlier, LTS 2.541.1 and earlier
https://www.jenkins.io/security/advisory/2026-02-18/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.441 and earlier, LTS 2.426.2 and earlier
https://www.jenkins.io/security/advisory/2024-01-24/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier
https://www.jenkins.io/security/advisory/2025-12-10/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.470 and earlier, LTS 2.452.3 and earlier
https://www.jenkins.io/security/advisory/2024-08-07/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.393 and earlier, LTS 2.375.3 and earlier
https://www.jenkins.io/security/advisory/2023-03-08/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier
https://www.jenkins.io/security/advisory/2025-04-02/
Jenkins core: Stored XSS vulnerability
https://www.jenkins.io/security/advisory/2023-07-26/
Jenkins core: HTTP/2 denial of service vulnerabilities in bundled Jetty
https://www.jenkins.io/security/advisory/2023-10-18/
Jenkins core: Denial of service vulnerability in bundled json-lib
https://www.jenkins.io/security/advisory/2024-11-27/
Jenkins core: HTTP/2 denial of service vulnerability in bundled Jetty
https://www.jenkins.io/security/advisory/2024-03-20/
Jenkins core: CSRF bypass vulnerability
https://www.jenkins.io/security/advisory/2023-06-14/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier
https://www.jenkins.io/security/advisory/2025-03-05/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.554 and earlier, LTS 2.541.2 and earlier
https://www.jenkins.io/security/advisory/2026-03-18/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.478 and earlier, LTS 2.462.2 and earlier
https://www.jenkins.io/security/advisory/2024-10-02/
Jenkins core: Multiple security vulnerabilities in Jenkins 2.423 and earlier, LTS 2.414.1 and earlier
https://www.jenkins.io/security/advisory/2023-09-20/
Loading...
API Token
Generate a legacy API token for each newly created user (Not recommended)
?
Loading...
Allow users to manually create a legacy API token (Not recommended)
?
Loading...
Enable API Token usage statistics
?
Loading...