QID 730043
QID 730043: Jenkins Plugin Installation Manager Crafted Plugin Downloads Vulnerability
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
Affected Versions:
Plugin Installation Manager Tool 2.1.3 and earlier
Fixed Versions:
Plugin Installation Manager Tool 2.2.0
Docker images of Jenkins 2.269 and 2.263.1 contain Plugin Installation Manager Tool 2.2.0
QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version by sending a crafted GET request to Jenkins. This QID also detects the vulnerable version from login page or HTTP header.
Plugin Installation Manager Tool does not verify plugin downloads. This may allow third parties such as mirror operators to provide crafted plugin downloads.
For further details refer to Jenkins Security Advisory 2020-12-03
- Jenkins Security Advisory 2020-12-03 -
www.jenkins.io/security/advisory/2020-12-03/#SECURITY-1856
CVEs related to QID 730043
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Jenkins Security Advisory 2020-12-03 |
|