QID 379473

Date Published: 2024-03-19

QID 379473: Jenkins Plugins Multiple Security Vulnerabilities (Jenkins Security Advisory 2024-03-06)

Jenkins is a self-contained Java-based program, ready to run out-of-the-box, with packages for Windows, Linux, macOS and other Unix-like operating systems.

Affected Product versions:
GitBucket Plugin 0.8 and earlier versions.
Subversion Partial Release Manager Plugin 1.0.1 and earlier versions.
IceScrum Plugin 1.1.6 and earlier versions.

QID Detection Logic:
This QID checks for installed Jenkins plugins using the function "check_jenkins_plugin_version" and then matches the version using regex.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, confidentiality and availability of the data.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customer are advised to update the installed plugins in Jenkins.
    For more information visit Jenkins Security Advisory 2024-03-06.

    Vendor References

    CVEs related to QID 379473

    Software Advisories
    Advisory ID Software Component Link