QID 376435

Date Published: 2022-03-14

QID 376435: Jenkins Plugins Multiple Security Vulnerabilities (Jenkins Security Advisory 2022-02-15)

Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.

Affected Versions:
Pipeline: Groovy Plugin 2648.va9433432b33c and earlier
Pipeline: Shared Groovy Libraries 552.vd9cc05b8a2e1 and earlier
Pipeline: Multibranch 706.vd43c65dec013 and earlier

QID Detection Logic:(Authenticated)
This QID checks for vulnerable versions of Jenkins plugin installed on the target.

Successful exploitation of these vulnerabilities may allow an issues may allow an attacker with Item/Configure permission to invoke arbitrary OS commands on the targeted system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customer are advised to update the installed plugins in Jenkins.
    For more information visit Jenkins Security Advisory 2022-02-15
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    https://www.jenkins.io/security/advisory/2022-02-15/ URL Logo www.jenkins.io/security/advisory/2022-02-15/