https://seclists.org/oss-sec/2026/q3/802: Multiple vulnerabilities in Jenkins plugins
Published Sep 16, 2026
·Updated
Affected Software
13 affected components
Jenkins Script Security Plugin<1415.v9a_f9b_3a_c253d
Jenkins Pipeline: Multibranch Plugin<=842.v3a_b_59b_57b_e6e
Jenkins Pipeline: Groovy Libraries Plugin<=806.v408277b_33d1d
Jenkins Gradle Plugin<=2.20.1253.vc116f0763a_eb_
Jenkins GitLab Plugin<=1.2152.veec0897048b_0
Jenkins Warnings Plugin<=13.10259.v80f407cb_03a_e
Jenkins Coverage Plugin<=3.3361.v0626103a_67e6
Jenkins OWASP Dependency-Check Plugin<=5.6.5
Jenkins Robot Framework Plugin<=6.3.0
Jenkins Bitbucket Server Integration Plugin<=6.0.2
Jenkins Bitbucket Push and Pull Request Plugin<=4.1.0
Jenkins Gitee Plugin<=1304.v2702f1d71cde
Jenkins Keycloak Authentication Plugin<=2.4.2
Frequently Asked Questions
1
What versions should be deployed to obtain the available fixes?
Upgrade to Bitbucket Push and Pull Request 4.1.0, Bitbucket Server Integration 6.0.2, Coverage 3.3361.v0626103a_67e6, Gitee 1304.v2702f1d71cde, GitLab 1.2152.veec0897048b_0, Gradle 2.20.1253.vc116f0763a_eb_, Keycloak Authentication 2.4.2, OWASP Dependency-Check 5.6.5, Pipeline: Groovy Libraries 806.v408277b_33d1d, Pipeline: Multibranch 842.v3a_b_59b_57b_e6e, Robot Framework 6.3.0, Script Security 1422.v06869826dd9b_, and Warnings 13.10259.v80f407cb_03a_e.
2
Where are vulnerability-specific severity and attribution details available?
The notice states that severity, attribution, and additional vulnerability details are available in the referenced Jenkins security advisory dated 2026-09-16.