Jenkins is a popular open-source automation server for building, testing, and deploying software. The vulnerability in question allows attackers to access build authorization tokens stored unencrypted in job config.xml files on the Jenkins controller.