Your review has been sent successfully

Jenkins Alert

2341
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

22 September, 2022

● High

2022-5264

All

Description:

Jenkins has released a security update to address vulnerabilities in the following products:

  • Jenkins (core)
  • Anchore Container Image Scanner Plugin
  • Apprenda Plugin
  • BigPanda Notifier Plugin
  • Build-Publisher Plugin
  • Compuware Common Configuration Plugin
  • CONS3RT Plugin
  • DotCi Plugin
  • extreme-feedback Plugin
  • NS-ND Integration Performance Publisher Plugin
  • NS-ND Integration Performance Publisher Plugin
  • RQM Plugin
  • Rundeck Plugin
  • SCM HttpClient Plugin
  • Security Inspector Plugin
  • SmallTest Plugin
  • View26 Test-Reporting Plugin
  • Walti Plugin
  • WildFly Deployer Plugin
  • Worksoft Execution Manager Plugin
Threats:

Attackers could exploit these vulnerabilities by doing the following:

  • Cross-site scripting (XSS)
  • Remote code execution (RCE)
  • Path traversal
Best practice and Recommendations:

The CERT team encourages users to update the affected versions and to review Jenkins security advisory:

Last updated at 22 September, 2022

Rate the content

rate-icon
up icon