Jenkins Update
2926Warning Date
Severity Level
Warning Number
Target Sector
26 March, 2020
● High
2020-1061
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following deliverables:
- Jenkins weekly
- up to and including 2.227
- Jenkins LTS
- up to and including 2.204.5
- Artifactory Plugin
- up to and including 3.6.0
- Azure Container Service Plugin
- up to and including 1.0.1
- OpenShift Pipeline Plugin
- up to and including 1.0.56
- Pipeline: AWS Steps Plugin
- up to and including 1.40
- Queue cleanup Plugin
- up to and including 1.3
- RapidDeploy Plugin
- up to and including 4.2
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code remotely.
- Cross-site scripting (XSS) attack.
- Cross-site request forgery (CSRF).
- Credentials stored in plain text.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: