Jenkins Security Bulletin: Multiple CVEs (Info Leak, Bypass, Credential Leak, OIDC Auth)
Security Advisory
SA-CORE-2024-10-02
High
Jenkins
Affected:
- Jenkins weekly <= 2.478
- Jenkins LTS <= 2.462.2
- Credentials plugin <= 1380.va_435002fa_924
- OpenID Authentication plugin <= 4.354.v321ce67a_1de8
Fixed in:
- Jenkins weekly 2.479+
- Jenkins LTS 2.462.3+
- Credentials plugin 1380.va_435002fa_924+
- OpenID Authentication plugin 4.354.v321ce67a_1de8+
Referenced CVEs:
CVE-2024-47807
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from www.jenkins.io, cleaned by our LLM pipeline, and translated to English. View original.