Jenkins Plugin Security Advisory: RCE, XXE, CSRF Bypass (CVE-2021-21677-21681)
Security AdvisorySA-CORE-2021-005HighJenkins
Affected:
- Code Coverage Plugin <= 1.4.0
- SAML Plugin <= 2.0.7
- Microsoft Entra ID (previously Azure AD) Plugin <= 179.vf6841393099e
- Nested View Plugin <= 1.20
- Nomad Plugin <= 0.7.4
Fixed in:
- Code Coverage Plugin 1.4.1
- Microsoft Entra ID (previously Azure AD) Plugin 180.v8b1e80e6f242
- Nested View Plugin 1.21
- Nomad Plugin 0.7.5
- SAML Plugin 2.0.8
Referenced CVEs: CVE-2021-21677
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from www.jenkins.io, cleaned by our LLM pipeline, and translated to English. View original.