Critical Vulnerabilities in Jenkins Server Lead to RCE
ID: f8a7a222-6fc4-533d-84b7-31432fa713f7
STIX ID: report--f8a7a222-6fc4-533d-84b7-31432fa713f7
Feed Name: Aqua Security Blog
**Executive Summary:** Aqua Nautilus disclosed CorePlague, two critical Jenkins vulnerabilities where unsanitized plugin metadata in the Jenkins Update Center can deliver a stored XSS that, when rendered by a vulnerable Jenkins Server's Available Plugin Manager, allows an attacker to execute arbitrary JavaScript as an admin and escalate to remote code execution via the Jenkins Script Console; patches for the Update Center and Jenkins Server were released in Feb–Mar 2023 and the report includes exploitation details, tiering limitations, attack steps, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
