Jenkins Alert
2141Warning Date
Severity Level
Warning Number
Target Sector
12 July, 2023
● High
2023-5670
All
Jenkins has released security updates to address multiple vulnerabilities in the following products:
- External Monitor Job Type Plugin
- OpenShift Login Plugin
- mabl Plugin
- Pipeline restFul API Plugin
Attackers could exploit these vulnerabilities by doing the following:
- CSRF Protection Bypass
- XML External Entity (XXE) attacks
- Session Fixation
The CERT team encourages users to update the affected versions and to review Jenkins security advisory: