Jenkins Update
2619Warning Date
Severity Level
Warning Number
Target Sector
7 May, 2020
● Medium
2020-1211
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following products:
- Amazon EC2 Plugin up to and including 1.50.1
- Copy Artifact Plugin up to and including 1.43.1
- Credentials Binding Plugin up to and including 1.22
- CVS Plugin up to and including 2.15
- SCM Filter Jervis Plugin up to and including 0.2.1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code.
- Elevate privileges
- Cross-site request forgery (CSRF)
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: