Jenkins Update
1781Warning Date
Severity Level
Warning Number
Target Sector
31 March, 2021
● High
2021-2704
All
Description:
Jenkins has released a security update to address a vulnerability in the following product:
- Build With Parameters Plugin
- up to and including 1.5
- Cloud Statistics Plugin
- up to and including 0.26
- Extra Columns Plugin
- up to and including 1.22
- Jabber (XMPP) notifier and control Plugin
- up to and including 1.41
- OWASP Dependency-Track Plugin
- up to and including 3.1.0
- REST List Parameter Plugin
- up to and including 1.3.0
- Team Foundation Server Plugin
- up to and including 5.157.1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Escalation of privilege
- Cross-site scripting (XSS)
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary update: