Jenkins Update
2502Warning Date
Severity Level
Warning Number
Target Sector
11 October, 2020
● Medium
2020-1901
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following deliverables:
- Active Choices Plugin up to and including 2.4
- Audit Trail Plugin up to and including 3.6
- couchdb-statistics Plugin up to and including 0.3
- Maven Cascade Release Plugin up to and including 1.3.2
- Nerrvana Plugin up to and including 1.02.06
- Persona Plugin up to and including 2.4
- Release Plugin up to and including 2.10.2
- Role-based Authorization Strategy Plugin up to and including 3.0
- Shared Objects Plugin up to and including 0.44
- SMS Notification Plugin up to and including 1.2
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack.
- Bypass of a protection mechanism.
- Elevate privileges.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: