Jenkins Security Advisory: Multiple Plugins Vulnerabilities (CVE-2020-2229-2237) including XSS, CSRF, and Missing Permission Checks
Security AdvisoryHighJenkins
Affected:
- Jenkins 2.251 and earlier
- Jenkins LTS 2.235.3 and earlier
- Email Extension Plugin 2.72 and 2.73
- Pipeline Maven Integration Plugin 3.8.2 and earlier
- Yet Another Build Visualizer Plugin 1.11 and earlier
Fixed in:
- Jenkins 2.252
- Jenkins LTS 2.235.4
- Email Extension Plugin 2.74
- Pipeline Maven Integration Plugin 3.8.3
- Yet Another Build Visualizer Plugin 1.12
Referenced CVEs: CVE-2020-2235 CVE-2020-2234
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from jenkins.io, cleaned by our LLM pipeline, and translated to English. View original.