Summary
August Jenkins Security Advisory released, addressing 2 vulnerabilities, one of which is “critical,” in Jenkins (Core) weekly and LTS.
Risk
Estimate of vulnerability impact on the reference community: HIGH/ORANGE (65.38/100)1.
Type
- Remote Code Execution
Affected products and versions
Jenkins Core
- weekly, versions prior to 2.471
- LTS, versions prior to 2.52.4 and 2.462.1
Mitigation actions
In line with vendor statements, it is recommended to update the affected products following the instructions in the security bulletin, available at the link in the References section.
Unique Vulnerability Identifiers
Here are only the CVEs related to the vulnerabilities with severity “critical”:
References
https://www.jenkins.io/security/advisory/2024-08-07
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoC, diffusion of the affected software/devices in the reference community.