QID 730752
Date Published: 2023-03-21
QID 730752: Jenkins Multiple Security Vulnerabilities (SECURITY-2823, SECURITY-1807, SECURITY-3058)
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
Affected versions:
Jenkins weekly up to and including 2.393
Jenkins LTS up to and including 2.375.3
Fixed Version:
Jenkins weekly should be updated to version 2.394
Jenkins LTS should be updated to version 2.375.4 or 2.387.1
QID Detection Logic (unauthenticated):
This QID checks for vulnerable version of Jenkins by sending a GET request to /login page and checking the version from the response received.
Note: As it has a mitigation hence making detection potential/practice
A successful exploit could be resulting in Jenkins arbitrary code execution, information disclosure
For further details refer to Jenkins Security Advisory 2023-03-08
- Jenkins Security Advisory 2023-03-08 -
www.jenkins.io/security/advisory/2023-03-08/
CVEs related to QID 730752
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Jenkins Security Advisory 2023-03-08 |
|