Jenkins Alert
7601Warning Date
Severity Level
Warning Number
Target Sector
20 September, 2023
● High
2023-5802
All
Description:
Jenkins has released security updates to address multiple vulnerabilities in the following products:
- Jenkins weekly up to and including 2.423
- Jenkins LTS up to and including 2.414.1
- Build Failure Analyzer Plugin up to and including 2.4.1
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Arbitrary Code Execution
- Cross-Site Scripting XSS
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and update the affected products: