Lucene search

K
redhatRedHatRHSA-2023:3195
HistoryMay 17, 2023 - 4:15 p.m.

(RHSA-2023:3195) Important: jenkins and jenkins-2-plugins security update

2023-05-1716:15:17
access.redhat.com
29
jenkins
security update
rce
xss
cve
continuous integration
server
vulnerability
apache
common-text
script security plugin
junit plugin
pipeline-build-step
information disclosure
error stack traces
unix

0.972 High

EPSS

Percentile

99.8%

Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron.

Security Fix(es):

  • apache-commons-text: variable interpolation RCE (CVE-2022-42889)

  • jenkins-2-plugins/script-security: Sandbox bypass vulnerability in Script Security Plugin (CVE-2023-24422)

  • jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin (CVE-2023-25761)

  • jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin (CVE-2023-25762)

  • Jenkins: Temporary file parameter created with insecure permissions (CVE-2023-27903)

  • Jenkins: Information disclosure through error stack traces related to agents (CVE-2023-27904)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

OSVersionArchitecturePackageVersionFilename
RedHat8noarchjenkins-2-plugins<Β 4.12.1683009955-1.el8jenkins-2-plugins-4.12.1683009955-1.el8.noarch.rpm
RedHat8noarchjenkins<Β 2.387.1.1683009767-3.el8jenkins-2.387.1.1683009767-3.el8.noarch.rpm