First published: Wed Sep 30 2020(Updated: )
Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron.<br>Security Fix(es):<br><li> jetty: double release of resource can lead to information disclosure (CVE-2019-17638)</li> <li> jenkins: user-specified tooltip values leads to stored cross-site scripting (CVE-2020-2229)</li> <li> jenkins: stored XSS vulnerability in project naming strategy (CVE-2020-2230)</li> <li> jenkins: stored XSS vulnerability in 'trigger builds remotely' (CVE-2020-2231)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <2.235.5.1600414805-1.el7 | 2.235.5.1600414805-1.el7 |
redhat/jenkins | <2.235.5.1600414805-1.el7 | 2.235.5.1600414805-1.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.