Thanks to ElColmo it has come to our attention that existing deployments of TurnKey Jenkins are still vulnerable to CVE-2015-8103, a critical issue that allows remote code execution by unauthenticated users.
This issue has been fixed with many others by the Jenkins project, as detailed in the 2015-11-11 Jenkins Security Advisory.