(RHSA-2024:0775) Important: jenkins and jenkins-2-plugins security update
Discription

Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron. Security Fix(es): apache-commons-text: variable interpolation RCE (CVE-2022-42889) SnakeYaml: Constructor Deserialization Remote Code Execution (CVE-2022-1471) maven-shared-utils: Command injection via Commandline class (CVE-2022-29599) jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin (CVE-2023-24422) Jenkins: Session fixation vulnerability in OpenShift Login Plugin (CVE-2023-37946) jenkins: Arbitrary file read vulnerability through the CLI can lead to RCE (CVE-2024-23897) jenkins: cross-site WebSocket hijacking (CVE-2024-23898) jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin (CVE-2023-25761) jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin (CVE-2023-25762) Jenkins: Temporary file parameter created with insecure permissions (CVE-2023-27903) Jenkins: Information disclosure through error stack traces related to agents (CVE-2023-27904) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References…Read More

Back to Main

Subscribe for the latest news: