[NEU] [hoch] Jenkins: Mehrere Schwachstellen
BSI flags multiple high-severity Jenkins and plugin vulnerabilities — including RCE and session hijacking — that could let attackers poison CI/CD pipelines from the outside.
Summary written by editorial AI · Source link below
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Jenkins und verschiedenen Plugins ausnutzen, um Daten offenzulegen oder zu manipulieren, Cross-Site Scripting (XSS) durchzuführen, beliebigen Code auszuführen oder die Sitzung eines anderen Benutzers zu übernehmen.
Editorial Analysis
A compromised Jenkins instance is a direct path to supply-chain attacks; these flaws allow unauthenticated attackers to execute code and hijack sessions on the build server.
Patch Jenkins core and all listed plugins immediately, restrict controller network access, and rotate credentials stored in Jenkins.
Vulnerabilities in the widely used Jenkins CI/CD platform could allow external attackers to tamper with software builds — immediate patching is required.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at CERT-Bund (BSI) in a new tab.
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d