Jenkins Security Advisory: XXE, Plaintext Passwords, and Missing Permission Checks in Plugins
Security AdvisorySA-2023-07-12HighJenkins
Affected:
- Active Directory Plugin <= 2.3.0
- Assembla Auth Plugin
- Benchmark Evaluator Plugin
- Datadog Plugin <= 5.4.1
- ElasticBox CI Plugin
Fixed in:
- Active Directory Plugin > 2.3.0
- Datadog Plugin > 5.4.1
- External Monitor Job Type Plugin >= 207.v98a_a_37a_85525
- SAML Single Sign On(SSO) Plugin > 2.3.0
Referenced CVEs: CVE-2023-37946
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from www.jenkins.io, cleaned by our LLM pipeline, and translated to English. View original.