QID 11718

Date Published: 2021-05-13

QID 11718: Jenkins Core Privilege Escalation Vulnerability(Jenkins Security Advisory 2021-02-19)

Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.

Affected Versions:
Jenkins weekly up to and including 2.279

Fixed Versions:
Jenkins weekly should be updated to version 2.280

QID Detection Logic:(Authenticated)
This QID checks for vulnerable versions of Jenkins installed on the target.

Allows attackers with Job/Workspace permission to exploit this to switch their identity to SYSTEM, an internal user with all permissions.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customer are advised, to installed the latest version of Jenkins.
    For more information visit Jenkins Security Advisory 2021-02-19
    Vendor References

    CVEs related to QID 11718

    Software Advisories
    Advisory ID Software Component Link
    Jenkins Security Advisory 2021-02-19 URL Logo www.jenkins.io/security/advisory/2021-02-19/