Jenkins Alert
2341Warning Date
Severity Level
Warning Number
Target Sector
22 September, 2022
● High
2022-5264
All
Jenkins has released a security update to address vulnerabilities in the following products:
- Jenkins (core)
- Anchore Container Image Scanner Plugin
- Apprenda Plugin
- BigPanda Notifier Plugin
- Build-Publisher Plugin
- Compuware Common Configuration Plugin
- CONS3RT Plugin
- DotCi Plugin
- extreme-feedback Plugin
- NS-ND Integration Performance Publisher Plugin
- NS-ND Integration Performance Publisher Plugin
- RQM Plugin
- Rundeck Plugin
- SCM HttpClient Plugin
- Security Inspector Plugin
- SmallTest Plugin
- View26 Test-Reporting Plugin
- Walti Plugin
- WildFly Deployer Plugin
- Worksoft Execution Manager Plugin
Attackers could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS)
- Remote code execution (RCE)
- Path traversal
The CERT team encourages users to update the affected versions and to review Jenkins security advisory: