Jenkins Update
2838Warning Date
Severity Level
Warning Number
Target Sector
24 September, 2020
● High
2020-1826
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following deliverables:
- Implied Labels Plugin
- up to and including 0.6
- Liquibase Runner Plugin
- up to and including 1.4.5
- Liquibase Runner Plugin
- up to and including 1.4.7
- Lockable Resources Plugin
- up to and including 2.8
- Script Security Plugin
- up to and including 1.74
- Warnings Plugin
- up to and including 5.0.1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack.
- Cross-site request forgery (CSRF).
- Missing permission check.
- Arbitrary code execution.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: