https://seclists.org/oss-sec/2026/q3/802: Multiple vulnerabilities in Jenkins plugins

Published Sep 16, 2026
·
Updated

Affected Software

13 affected components
Jenkins Script Security Plugin<1415.v9a_f9b_3a_c253d
Jenkins Pipeline: Multibranch Plugin<=842.v3a_b_59b_57b_e6e
Jenkins Pipeline: Groovy Libraries Plugin<=806.v408277b_33d1d
Jenkins Gradle Plugin<=2.20.1253.vc116f0763a_eb_
Jenkins GitLab Plugin<=1.2152.veec0897048b_0
Jenkins Warnings Plugin<=13.10259.v80f407cb_03a_e
Jenkins Coverage Plugin<=3.3361.v0626103a_67e6
Jenkins OWASP Dependency-Check Plugin<=5.6.5
Jenkins Robot Framework Plugin<=6.3.0
Jenkins Bitbucket Server Integration Plugin<=6.0.2
Jenkins Bitbucket Push and Pull Request Plugin<=4.1.0
Jenkins Gitee Plugin<=1304.v2702f1d71cde
Jenkins Keycloak Authentication Plugin<=2.4.2

Frequently Asked Questions

1

What versions should be deployed to obtain the available fixes?

Upgrade to Bitbucket Push and Pull Request 4.1.0, Bitbucket Server Integration 6.0.2, Coverage 3.3361.v0626103a_67e6, Gitee 1304.v2702f1d71cde, GitLab 1.2152.veec0897048b_0, Gradle 2.20.1253.vc116f0763a_eb_, Keycloak Authentication 2.4.2, OWASP Dependency-Check 5.6.5, Pipeline: Groovy Libraries 806.v408277b_33d1d, Pipeline: Multibranch 842.v3a_b_59b_57b_e6e, Robot Framework 6.3.0, Script Security 1422.v06869826dd9b_, and Warnings 13.10259.v80f407cb_03a_e.

2

Where are vulnerability-specific severity and attribution details available?

The notice states that severity, attribution, and additional vulnerability details are available in the referenced Jenkins security advisory dated 2026-09-16.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203