Jenkins Patches High-Severity Plugin Vulnerability Including Path Traversal and Stored XSS
ID: c0eb568c-9502-5fcb-a24b-3aa0e8ee4cd3
STIX ID: report--c0eb568c-9502-5fcb-a24b-3aa0e8ee4cd3
Feed Name: Cyber Press
Jenkins published a security advisory (April 29, 2026) addressing seven plugin vulnerabilities—three High severity—that include a path traversal leading to possible remote code execution (CVE-2026-42520) in the Credentials Binding Plugin, stored XSS in the GitHub and HTML Publisher plugins, unsafe deserialization, missing permission checks, and an open redirect. The advisory lists affected versions and fixed releases for each CVE and urges administrators to immediately apply the patched plugin versions via the Jenkins Plugin Manager, prioritizing the Credentials Binding and GitHub Plugin updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
