QID 11718
Date Published: 2021-05-13
QID 11718: Jenkins Core Privilege Escalation Vulnerability(Jenkins Security Advisory 2021-02-19)
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
Affected Versions:
Jenkins weekly up to and including 2.279
Fixed Versions:
Jenkins weekly should be updated to version 2.280
QID Detection Logic:(Authenticated)
This QID checks for vulnerable versions of Jenkins installed on the target.
Allows attackers with Job/Workspace permission to exploit this to switch their identity to SYSTEM, an internal user with all permissions.
Solution
Customer are advised, to installed the latest version of Jenkins.
For more information visit Jenkins Security Advisory 2021-02-19
For more information visit Jenkins Security Advisory 2021-02-19
Vendor References
- Jenkins Security Advisory 2021-02-19 -
www.jenkins.io/security/advisory/2021-02-19/
CVEs related to QID 11718
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Jenkins Security Advisory 2021-02-19 |
|