Jenkins Alert
2690Warning Date
Severity Level
Warning Number
Target Sector
17 May, 2023
● Critical
2023-5596
All
Jenkins has released security updates to address several vulnerabilities in the following products:
- Pipeline: Job Plugin
- TestNG Results Plugin
- File Parameter Plugin
- SAML Single Sign On (SSO) Plugin
- CAS Plugin
- TestComplete support Plugin
- WSO2 Oauth Plugin
- LoadComplete support Plugin
Attackers could exploit this vulnerability by doing the following:
- Stored Cross-site scripting (XSS)
- Arbitrary File writes
- XML External Entity (XXE) attacks
- Session Fixation
The CERT team encourages users to update the affected versions and to review Jenkins security advisory: