QID 730835
Date Published: 2023-07-17
QID 730835: Jenkins Multiple Security Vulnerabilities (SECURITY-3135)
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
Affected versions:
Jenkins 2.399 and earlier
LTS 2.387.3 and earlier
Fixed Version:
Jenkins weekly should be updated to version 2.400
Jenkins LTS should be updated to version 2.401.1
QID Detection Logic (unauthenticated):
This QID checks for vulnerable version of Jenkins by sending a GET request to /login page and checking the version from the response received.
A successful exploit could result in CSRF protection bypass vulnerability.
Solution
Customers are advised to upgrade to latest Jenkins version
For further details refer to Jenkins Security Advisory 2023-06-14
For further details refer to Jenkins Security Advisory 2023-06-14
Vendor References
- Jenkins Security Advisory 2023-06-14 -
www.jenkins.io/security/advisory/2023-06-14/
CVEs related to QID 730835
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Jenkins Security Advisory 2023-06-14 |
|