Jenkins Security Advisory: Sandbox Bypass and Stored XSS in Multiple Plugins (CVE-2020-2109 to 2113)
Security AdvisoryHighJenkins
Affected:
- Jenkins Pipeline: Groovy Plugin <= 2.78
- Jenkins Script Security Plugin <= 1.69
- Jenkins Subversion Plugin <= 2.13.0
- Jenkins Git Parameter Plugin <= 0.9.11
- Jenkins Brakeman Plugin <= 0.12
Fixed in:
- Pipeline: Groovy Plugin 2.79
- Script Security Plugin 1.70
- Subversion Plugin 2.13.1
- Git Parameter Plugin 0.9.12
- Brakeman Plugin 0.13
Referenced CVEs: CVE-2020-2116 CVE-2020-2117
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from jenkins.io, cleaned by our LLM pipeline, and translated to English. View original.