Jenkins Alert
2568Warning Date
Severity Level
Warning Number
Target Sector
30 March, 2022
● High
2022-4580
All
Description:
Jenkins has released a security update to address a vulnerabilities in the following products:
- Bitbucket Server Integration Plugin
- Continuous Integration with Toad Edge Plugin
- Coverage/Complexity Scatter Plot Plugin
- Flaky Test Handler Plugin
- instant-messaging Plugin
- JiraTestResultReporter Plugin
- Job and Node ownership Plugin
- Pipeline: Phoenix AutoTest Plugin
- Proxmox Plugin
- Proxmox Plugin
- Proxmox Plugin
- RocketChat Notifier Plugin
- SiteMonitor Plugin
- Tests Selector Plugin
Threats:
Attacker could exploit this vulnerabilities by doing the following:
- Cross-site scripting (XSS)
Best practice and Recommendations:
The CERT team encourages users to update the affected versions and to review Jenkins security advisory: