QID 376435
Date Published: 2022-03-14
QID 376435: Jenkins Plugins Multiple Security Vulnerabilities (Jenkins Security Advisory 2022-02-15)
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
Affected Versions:
Pipeline: Groovy Plugin 2648.va9433432b33c and earlier
Pipeline: Shared Groovy Libraries 552.vd9cc05b8a2e1 and earlier
Pipeline: Multibranch 706.vd43c65dec013 and earlier
QID Detection Logic:(Authenticated)
This QID checks for vulnerable versions of Jenkins plugin installed on the target.
Successful exploitation of these vulnerabilities may allow an issues may allow an attacker with Item/Configure permission to invoke arbitrary OS commands on the targeted system.
Solution
Customer are advised to update the installed plugins in Jenkins.
For more information visit Jenkins Security Advisory 2022-02-15
For more information visit Jenkins Security Advisory 2022-02-15
Vendor References
- Jenkins Advisory 2022-02-15 -
www.jenkins.io/security/advisory/2022-02-15/
CVEs related to QID 376435
CVE-2022-25173 | CVE-2022-25174 | CVE-2022-25175 | CVE-2022-25176 | CVE-2022-25177 | CVE-2022-25178 | CVE-2022-25179 | CVE-2022-25180 | CVE-2022-25181 | CVE-2022-25182 | CVE-2022-25183 | CVE-2022-25184 | CVE-2022-25185 | CVE-2022-25186 | CVE-2022-25187 | CVE-2022-25188 | CVE-2022-25189 | CVE-2022-25190 | CVE-2022-25191 | CVE-2022-25192 | CVE-2022-25193 | CVE-2022-25194 | CVE-2022-25195 | CVE-2022-25196 | CVE-2022-25197 | CVE-2022-25198 | CVE-2022-25199 | CVE-2022-25200 | CVE-2022-25201 | CVE-2022-25202 | CVE-2022-25203 | CVE-2022-25204 | CVE-2022-25205 | CVE-2022-25206 | CVE-2022-25207 | CVE-2022-25208 | CVE-2022-25209 | CVE-2022-25210 | CVE-2022-25211 | CVE-2022-25212 |
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| https://www.jenkins.io/security/advisory/2022-02-15/ |
|