Jenkins Update
2974Warning Date
Severity Level
Warning Number
Target Sector
16 January, 2020
● Medium
2020-805
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following deliverables:
- Amazon EC2 Plugin - up to and including 1.47
- Gitlab Hook Plugin - up to and including 1.4.2
- Health Advisor by CloudBees Plugin - up to and including 3.0
- Redgate SQL Change Automation Plugin - up to and including 2.0.4
- Robot Framework Plugin - up to and including 2.0.0
- Sounds Plugin - up to and including 0.5
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site request forgery (CSRF).
- Cross-site scripting (XSS) attack.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: