Jenkins Alert
1995Warning Date
Severity Level
Warning Number
Target Sector
6 September, 2023
● High
2023-5776
All
Jenkins has released security updates to address multiple vulnerabilities in the following products:
- jobConfigHistory Plugin
- qualys-cs Plugin
- ivy Plugin
- tap Plugin
An attacker could exploit these vulnerabilities by doing the following:
- Cross-Site Scripting XSS
- Path Traversal
- XML External Entity (XXE) attacks
The CERT team encourages users to review Jenkins security advisory and update the affected products: