QID 379054
Date Published: 2024-01-15
QID 379054: Jenkins Plugins Multiple Security Vulnerabilities (Jenkins Security Advisory 2023-10-25)
Jenkins is a self-contained Java-based program, ready to run out-of-the-box, with packages for Windows, Linux, macOS and other Unix-like operating systems.
Affected Product versions:
Jenkins GitHub Plugin 1.37.3 and earlier versions.
Warnings Plugin 10.5.0 and earlier versions.
lambdatest-automation Plugin 1.20.9 and earlier versions.
lambdatest-automation Plugin 1.20.10 and earlier versions.
CloudBees CD Plugin 1.1.32 and earlier versions.
CloudBees CD Plugin 1.1.32 and earlier versions.
Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier versions.
Gogs Plugin 1.0.15 and earlier versions.
MSTeams Webhook Trigger Plugin 0.1.1 and earlier versions.
Edgewall Trac Plugin 1.13 and earlier versions.
Zanata Plugin 0.6 and earlier versions.
Detection mechanism is implemented only for the availability of lambdatest-automation Plugin 1.21.0 as it will cover CVE-2023-46652 and CVE-2023-46653.
QID Detection Logic:
This QID checks for installed Jenkins plugins using the function "check_jenkins_plugin_version" and then matches the version using regex.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, confidentiality and availability of the data.
For more information visit Jenkins Security Advisory 2023-10-25.
- Jenkins Security Advisory 2023-10-25 -
www.jenkins.io/security/advisory/2023-10-25/
CVEs related to QID 379054
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Jenkins Security Advisory 2023-10-25 |
|