HomeSecurityJenkins fixes critical vulnerabilities in servers and plugins

Jenkins fixes critical vulnerabilities in servers and plugins

The open source CI/CD automation tool Jenkinshas released patches for multiple high and medium severity vulnerabilities in the server and several plugins.

See also: Chrome: Vulnerabilities allow hackers to execute arbitrary code

Jenkins vulnerabilities

Patches have been released for two medium severity vulnerabilities in Jenkins, one leading to multi-line secret disclosure and another leading to build restriction bypass.

The first issue, tracked as CVE-2024-47803, exists because “Jenkins 2.478 and earlier, LTS 2.462.2 and earlier do not strip multi-line secret values ​​in error messages generated for form submissions that include the secretTextarea form field,” according to a Jenkins security bulletin.

This could lead to the disclosure of multi-line secrets in messages present in the system logs and was addressed in Jenkins versions 2.479 and LTS 2.462.3 by editing these secrets.

Jenkins also announced patches for CVE-2024-47804, a vulnerability that affects the component creation functionality of the software development automation server.

See also: Vulnerabilities in Cisco Small Business Routers allow remote exploitation

While Jenkins can be configured to disallow the creation of specific types of assets, if the creation is attempted using the Jenkins CLI or REST API and one of the two specific checks fails, the asset will be created in memory and deleted from disk.

Jenkins fixes critical vulnerabilities in servers and plugins

Patches were also released for two high-severity vulnerabilities in the OpenId Connect Authentication plugin and a medium-severity flaw in the Credentials plugins.

The OpenId Connect authentication vulnerabilities — CVE-2024-47806 and CVE-2024-47807 — exist because the plugin fails to check whether a token was issued for the correct client and original issuer identity, which could allow attackers to gain access to Jenkins.

Known as CVE-2024-47805, the Credentials plugins issue exists because encrypted credentials values ​​using the SecretBytes are not cleared when accessing config.xml via REST API or CLI, allowing attackers with read/extended privileges to view these encrypted values.

See also: DrayTek routers: Vulnerabilities fixed in 24 models

Critical vulnerabilities are weaknesses within a system or network that could lead to significant harm if exploited by malicious actors. These vulnerabilities often allow attackers to gain unauthorized access to sensitive data, disrupt services , or take control of entire systems. They are critical in nature because they typically affect a large number of users or systems and have the potential to cause significant financial and reputational damage. Organizations should prioritize identifying and mitigating these vulnerabilities by implementing strong security measures, regular patching, and ongoing monitoring to protect their assets from potential threats.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS