Jenkins Security Advisory: XXE, Plaintext Passwords, and Missing Permission Checks in Plugins
Security AdvisorySA-2023-07-12HighJenkins
Affected:
- Active Directory Plugin <= 2.3.0
- Assembla Auth Plugin
- Benchmark Evaluator Plugin
- Datadog Plugin <= 5.4.1
- ElasticBox CI Plugin
Fixed in:
- Active Directory Plugin > 2.3.0
- Datadog Plugin > 5.4.1
- External Monitor Job Type Plugin >= 207.v98a_a_37a_85525
- SAML Single Sign On(SSO) Plugin > 2.3.0
参照 CVE: CVE-2023-37946
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 www.jenkins.io 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。