Jenkins Updates
2589Warning Date
Severity Level
Warning Number
Target Sector
7 November, 2021
● Critical
2021-3811
All
Description:
Jenkins has released a security updates to address multiple vulnerabilities in the following products:
- Jenkins weekly
- up to and including 2.318
- Jenkins LTS
- up to and including 2.303.2
- Subversion Plugin
- up to and including 2.15.0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Information disclosure
- Path traversal attack
- Arbitrary code execution
Best practice and Recommendations:
The CERT team encourages users to review Jenkins security advisory and apply the necessary updates: