QID 375517

Date Published: 2021-04-29

QID 375517: Jenkins Plugins Multiple Security Vulnerabilities(Jenkins Security Advisory 2021-04-07)

Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.

Affected Versions:
Micro Focus Application Automation Tools Plugin up to and including 6.7
promoted builds Plugin up to and including 3.9

Fixed Versions:
Micro Focus Application Automation Tools Plugin should be updated to version 6.8
Promoted builds Plugin should be updated to version 3.9.1

QID Detection Logic:(Authenticated)
This QID checks for vulnerable versions of Jenkins plugin installed on the target.

These vulnerabilities allow attackers to promote builds, allows attackers with Overall/Read permission to connect to attacker-specified URLs using attacker-specified username and password.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customer are advised to update the installed plugins in Jenkins.
    For more information visit Jenkins Security Advisory 2021-04-07
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    Jenkins Security Advisory 2021-04-07 URL Logo www.jenkins.io/security/advisory/2021-04-07/