Jenkins Update
3346Warning Date
Severity Level
Warning Number
Target Sector
30 January, 2020
● Medium
2020-860
All
Description:
Jenkins has released security update to address multiple vulnerabilities in the following products:
- Jenkins weekly
- up to and including 2.218
- Jenkins LTS
- up to and including 2.204.1
- Code Coverage API Plugin
- up to and including 1.1.2
- Fortify Plugin
- up to and including 19.1.29
- WebSphere Deployer Plugin
- up to and including 1.6.1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- XML external entity (XXE) attack
- Users who are not administrators can view JVM memory usage data.
- Cross-site scripting (XSS) attack.
- Routing the victim through a specially crafted web page.
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: