Jenkins Alert
2614Warning Date
Severity Level
Warning Number
Target Sector
23 June, 2022
● Medium
2022-4995
All
Description:
Jenkins has released a security update to address a vulnerabilities in the following products:
- Jenkins (core)
- Agent Server Parameter Plugin
- Beaker builder Plugin
- Convertigo Mobile Platform Plugin
- CRX Content Package Deployer Plugin
- Date Parameter Plugin
- Dynamic Extended Choice Parameter Plugin
- EasyQA Plugin
- Embeddable Build Status Plugin
- Filesystem List Parameter Plugin
- Hidden Parameter Plugin
- Image Tag Parameter Plugin
- Jianliao Notification Plugin
- JUnit Plugin
- Maven Metadata Plugin for Jenkins CI server Plugin
- Nested View Plugin
- NS-ND Integration Performance Publisher Plugin
- ontrack Jenkins Plugin
- Package Version Plugin
- Pipeline: Input Step Plugin
- Readonly Parameter Plugin
- Repository Connector Plugin
- REST List Parameter Plugin
- Sauce OnDemand Plugin
- Squash TM Publisher (Squash4Jenkins) Plugin
- Stash Branch Parameter Plugin
- ThreadFix Plugin
- vRealize Orchestrator Plugin
- xUnit Plugin
Threats:
Attacker could exploit this vulnerabilities by doing the following:
- Cross-site scripting (XSS)
- Path traversal attack
Best practice and Recommendations:
The CERT team encourages users to update the affected versions and to review Jenkins security advisory: