Jenkins Update
2904Warning Date
Severity Level
Warning Number
Target Sector
13 August, 2020
● High
2020-1640
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following products:
- Jenkins weekly up to and including 2.251
- Jenkins LTS up to and including 2.235.3
- Email Extension Plugin up to and including 2.73
- Flaky Test Handler Plugin up to and including 1.0.4
- Pipeline Maven Integration Plugin up to and including 3.8.2
- Yet Another Build Visualizer Plugin up to and including 1.11
Threats:
Attacker could exploit these vulnerabilities by conducting a cross-site scripting (XSS) attack.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: