Asked my team to review their Jenkins passwords and Jenkins user rights...
Do ask your team to review passwords and user rights, but also put this service and others like it behind a VPN. Then both the VPN server and Jenkins will have to have holes simultaneously before you get hacked.