Jenkins Plugin Security Bulletin: RCE, SSRF, LFI via LDAP/AD/Credentials
Security AdvisoryHighJenkins
Affected:
- Active Directory Plugin 2.41 and earlier
- AppSpider Plugin 1.0.17 and earlier
- Bitbucket OAuth Plugin 0.17 and earlier
- buildgraph-view Plugin 1.8 and earlier
- Credentials Binding Plugin 720.v3f6decef43ea_ and earlier
Fixed in:
- Active Directory Plugin 2.41.1
- AppSpider Plugin 1.0.18
- Bitbucket OAuth Plugin 0.18
- buildgraph-view Plugin not specified in summary
- Credentials Binding Plugin 725.ve52b_2328a_fde
参照 CVE: CVE-2026-48921
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 www.jenkins.io 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。