RHEL 8 : jenkins and jenkins-2-plugins (RHSA-2024:0776)
Discription

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2024:0776 advisory. maven: Block repositories using http by default (CVE-2021-26291) snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857) maven-shared-utils: Command injection via Commandline class (CVE-2022-29599) apache-commons-text: variable interpolation RCE (CVE-2022-42889) jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin (CVE-2023-24422) jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin (CVE-2023-25761) jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin (CVE-2023-25762) Jenkins: Session fixation vulnerability in OpenShift Login Plugin (CVE-2023-37946) jenkins: Arbitrary file read vulnerability through the CLI can lead to RCE (CVE-2024-23897) jenkins: cross-site WebSocket hijacking (CVE-2024-23898) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version…Read More

Back to Main

Subscribe for the latest news: