Jenkins多插件安全漏洞公告 (XSS/SSRF/权限绕过等)
Security AdvisorySA-CORE-2024-11HighJenkins
Affected:
- Authorize Project Plugin 1.7.2 and earlier
- IvyTrigger Plugin 1.01 and earlier
- OpenID Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier
- Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier
- Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier
Referenced CVEs: CVE-2024-52553
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 www.jenkins.io 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。