Jenkins Update
2881Warning Date
Severity Level
Warning Number
Target Sector
16 July, 2020
● High
2020-1505
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following deliverables:
- Jenkins weekly
- up to and including 2.244
- Jenkins LTS
- up to and including 2.235.1
- Deployer Framework Plugin
- up to and including 1.2
- Gitlab Authentication Plugin
- up to and including 1.5
- Matrix Authorization Strategy Plugin
- up to and including 2.6.1
- Matrix Project Plugin
- up to and including 1.16
Threats:
Attacker could exploit these vulnerabilities by conducting a cross-site scripting (XSS) attack.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: