Jenkins Alert
2869Warning Date
Severity Level
Warning Number
Target Sector
24 August, 2022
● High
2022-5153
All
Jenkins has released a security update to address vulnerabilities in the following products:
- Job Configuration History Plugin
- Kubernetes Continuous Deploy Plugin
Attackers could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS)
- Remote code execution (RCE)
The CERT team encourages users to update the affected versions and to review Jenkins security advisory: