Jenkins Patches High-Severity Plugin Flaws Including Path Traversal and Stored XSS
ID: 23008924-93e5-5f86-9619-9d12ac355710
STIX ID: report--23008924-93e5-5f86-9619-9d12ac355710
Feed Name: cybersecurityNews.com
Jenkins published a security advisory for seven plugin vulnerabilities: the most critical is CVE-2026-42520 (path traversal in Credentials Binding Plugin) that can lead to arbitrary file writes and potential remote code execution; two high-severity stored XSS issues (CVE-2026-42523 in the GitHub Plugin and CVE-2026-42524 in the HTML Publisher Plugin) permit JavaScript injection; and four medium-severity flaws affect the Script Security, Matrix Authorization Strategy, GitHub Branch Source, and Microsoft Entra ID plugins. All issues were reported via the Jenkins Bug Bounty Program and administrators are urged to apply patches immediately and consider enabling Content Security Policy on Jenkins LTS 2.541.1+ while remediating.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
