Jenkins Security Advisory: Stored XSS, CSRF, and Credential Exposure in Multiple Plugins (CVE-2023-39151 et al.)
Security AdvisoryHighJenkins
Affected:
- Jenkins weekly up to and including 2.415
- Jenkins LTS up to and including 2.401.2
- Bazaar Plugin up to and including 1.22
- Chef Identity Plugin up to and including 2.0.3
- GitLab Authentication Plugin up to and including 1.17.1
Fixed in:
- Jenkins weekly 2.416
- Jenkins LTS 2.401.3
- Jenkins LTS 2.414.1
- GitLab Authentication Plugin 1.18
- Gradle Plugin 2.8.1
参照 CVE: CVE-2023-39152
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 www.jenkins.io 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。