Jenkins Update
3121Warning Date
Severity Level
Warning Number
Target Sector
4 June, 2020
● Medium
2020-1311
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following deliverables:
- Compact Columns Plugin
- up to and including 1.11
- ECharts API Plugin
- up to and including 4.7.0-3
- Play Framework Plugin
- up to and including 1.0.2
- Project Inheritance Plugin
- up to and including 19.08.02
- Script Security Plugin
- up to and including 1.72
- Selenium Plugin
- up to and including 3.141.59
- Self-Organizing Swarm Plug-in Modules Plugin
- up to and including 3.20
- Subversion Partial Release Manager Plugin
- up to and including 1.0.1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack.
- Cross-site request forgery (CSRF).
- Missing permission check.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: