Jenkins Alert
2147Warning Date
Severity Level
Warning Number
Target Sector
16 August, 2023
● High
2023-5733
All
Description:
Jenkins has released security updates to address multiple vulnerabilities in the following products:
- Blue Ocean Plugin
- Config File Provider Plugin
- Delphix Plugin
- Docker Swarm Plugin
- Favorite View Plugin
- Flaky Test Handler Plugin
- Folders Plugin
- Fortify Plugin
- Gogs Plugin
- Maven Artifact ChoiceListProvider (Nexus) Plugin
- NodeJS Plugin
- Shortcut Job Plugin
- Tuleap Authentication Plugin
Threats:
Attackers could exploit these vulnerabilities by doing the following:
- Cross-Site Request Forgery (CSRF)
- Sensitive Information Disclosure
- Stored XSS
Best practice and Recommendations:
The CERT team encourages users to update the affected versions and to review Jenkins security advisory: