The open source CI/CD automation tool Jenkinshas released patches for multiple high and medium severity vulnerabilities in the server and several plugins.
See also: Chrome: Vulnerabilities allow hackers to execute arbitrary code

Patches have been released for two medium severity vulnerabilities in Jenkins, one leading to multi-line secret disclosure and another leading to build restriction bypass.
The first issue, tracked as CVE-2024-47803, exists because “Jenkins 2.478 and earlier, LTS 2.462.2 and earlier do not strip multi-line secret values in error messages generated for form submissions that include the secretTextarea form field,” according to a Jenkins security bulletin.
This could lead to the disclosure of multi-line secrets in messages present in the system logs and was addressed in Jenkins versions 2.479 and LTS 2.462.3 by editing these secrets.
Jenkins also announced patches for CVE-2024-47804, a vulnerability that affects the component creation functionality of the software development automation server.
See also: Vulnerabilities in Cisco Small Business Routers allow remote exploitation
While Jenkins can be configured to disallow the creation of specific types of assets, if the creation is attempted using the Jenkins CLI or REST API and one of the two specific checks fails, the asset will be created in memory and deleted from disk.

Patches were also released for two high-severity vulnerabilities in the OpenId Connect Authentication plugin and a medium-severity flaw in the Credentials plugins.
The OpenId Connect authentication vulnerabilities — CVE-2024-47806 and CVE-2024-47807 — exist because the plugin fails to check whether a token was issued for the correct client and original issuer identity, which could allow attackers to gain access to Jenkins.
Known as CVE-2024-47805, the Credentials plugins issue exists because encrypted credentials values using the SecretBytes are not cleared when accessing config.xml via REST API or CLI, allowing attackers with read/extended privileges to view these encrypted values.
See also: DrayTek routers: Vulnerabilities fixed in 24 models
Critical vulnerabilities are weaknesses within a system or network that could lead to significant harm if exploited by malicious actors. These vulnerabilities often allow attackers to gain unauthorized access to sensitive data, disrupt services , or take control of entire systems. They are critical in nature because they typically affect a large number of users or systems and have the potential to cause significant financial and reputational damage. Organizations should prioritize identifying and mitigating these vulnerabilities by implementing strong security measures, regular patching, and ongoing monitoring to protect their assets from potential threats.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
