Jenkins Plugin Security Advisory: XXE, CSRF, Unverified Downloads (CVE-2020-2320-2324)
Security AdvisoryHighJenkins
Affected:
- CVS plugin <= 2.16
- Plugin Installation Manager tool <= 2.1.3
- Shelve Project plugin <= 3.0
- Chaos Monkey plugin <= 0.4
Fixed in:
- CVS plugin 2.17
- Plugin Installation Manager tool 2.2.0
- Shelve Project plugin 3.1
- Chaos Monkey plugin 0.4.1
参照 CVE: CVE-2020-2324
本文由本平台从 www.jenkins.io 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。