Jenkins Update
2988Warning Date
Severity Level
Warning Number
Target Sector
9 April, 2020
● Medium
2020-1116
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following deliverables:
- AWSEB Deployment Plugin
- up to and including 0.3.19
- Code Coverage API Plugin
- up to and including 1.1.4
- FitNesse Plugin
- up to and including 1.31
- Gatling Plugin
- up to and including 1.2.7
- useMango Runner Plugin
- up to and including 1.4
Threats:
Attacker could exploit these vulnerabilities by conducting a cross-site scripting (XSS) attack.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: