QID 730045

Date Published: 2021-04-14

QID 730045: Jenkins Multiple Security Vulnerabilities(Jenkins Security Advisory 2021-04-07)

Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.

Affected Versions:
Jenkins weekly up to and including 2.286
Jenkins LTS up to and including 2.277.1

QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version by sending a crafted GET request to Jenkins. This QID also detects the vulnerable version from login page or HTTP header.

Successful exploitation of these vulnerabilities could affect Confidentiality, Integrity and Availability.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to upgrade to latest Jenkins version
    For further details refer to Jenkins Security Advisory 2021-04-07
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    Jenkins Security Advisory 2021-04-07 URL Logo www.jenkins.io/security/advisory/2021-04-07/