Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cloudbees Jenkins 代码问题漏洞
Vulnerability Description
Cloudbees Jenkins(Hudson Labs)是美国CloudBees(Cloudbees)公司的一套基于Java开发的持续集成工具。该产品主要用于监控持续的软件版本发布/测试项目和一些定时执行的任务。 Jenkins 2.274版本及之前存在代码问题漏洞,该漏洞源于程序允许具有权限的攻击者利用该漏洞创建或配置各种对象,将精心制作的内容注入到旧的Data Monitor中,从而导致管理员丢弃的潜在不安全对象的实例化。以下设备或型号存在漏洞:Jenkins 2.274版本及之前、LTS 2.2
CVSS Information
N/A
Vulnerability Type
N/A