Jenkins Security Advisory: CVEs for Agent-to-Controller Deserialization Bypass, Arbitrary File Creation, and CSRF RCE
Security AdvisoryUnknownJenkins
Affected:
- Jenkins 2.575 或更早版本
- Jenkins LTS 2.568.1 或更早版本
- Multijob 插件 669.v9d96a_d9c71b_0 或更早版本
- HCL AppScan 插件 1.8.3 或更早版本
- SCM-Manager 插件 1.11.1 或更早版本
Fixed in:
- Jenkins 2.576
- Jenkins LTS 2.568.2
- Multijob 插件 677.v7ffc23d6a_4c2
- HCL AppScan 插件 1.8.4
- SCM-Manager 插件 1.12.1
参照 CVE: CVE-2026-70442
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 www.jenkins.io 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。