High-Severity RCE and XSS Flaws Found in Popular CI/CD Jenkins Plugins
ID: 8f616530-6a57-557f-af89-2c4233846ee9
STIX ID: report--8f616530-6a57-557f-af89-2c4233846ee9
Feed Name: securityonline.info
Threat Score
Jenkins published an advisory describing multiple plugin vulnerabilities—notably a high-severity path traversal in the Credentials Binding plugin that can lead to remote code execution, and stored XSS flaws in the GitHub and HTML Publisher plugins—plus several medium-severity issues (unsafe deserialization, missing permission checks, open redirect). Administrators are urged to apply the listed plugin updates immediately to mitigate widespread CI/CD exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
