Jenkins多插件安全漏洞公告(XSS/SSRF/沙箱绕过/会话劫持)
Security AdvisoryHighJenkins
Affected:
- Authorize Project Plugin <= 1.7.2
- IvyTrigger Plugin <= 1.01
- OpenID Connect Authentication Plugin <= 4.418.vccc7061f5b_6d
- Pipeline: Declarative Plugin <= 2.2214.vb_b_34b_2ea_9b_83
- Pipeline: Groovy Plugin <= 3990.vd281dd77a_388
Referenced CVEs: CVE-2024-52551
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 www.jenkins.io 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。