Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-27016

Jenkins runs as LOCAL SYSTEM privilege on Windows

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • packaging
    • None
    • Jenkins 1.599, Windows Server

      By default, the Jenkins service wrapper is configured to launch as the local system account on Windows. This is an elevated privilege (i.e. root) account.

      The installer should prompt users to choose an account (similar to how Microsoft SQL Server does) under which the Jenkins service and associated java process should run.

      This is a highly insecure default configuration which encourages bad practice and implementation by less experienced users.

            slide_o_mix Alex Earl
            mcramer Michael Cramer
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: