logo

Critical Vulnerabilities in Jenkins Server Lead to RCE

ID: f8a7a222-6fc4-533d-84b7-31432fa713f7

STIX ID: report--f8a7a222-6fc4-533d-84b7-31432fa713f7

Feed Name: Aqua Security Blog

Threat Score
80/100

Date Published: 2023-03-08

Date Updated: 2026-04-26

...
...

**Executive Summary:** Aqua Nautilus disclosed CorePlague, two critical Jenkins vulnerabilities where unsanitized plugin metadata in the Jenkins Update Center can deliver a stored XSS that, when rendered by a vulnerable Jenkins Server's Available Plugin Manager, allows an attacker to execute arbitrary JavaScript as an admin and escalate to remote code execution via the Jenkins Script Console; patches for the Update Center and Jenkins Server were released in Feb–Mar 2023 and the report includes exploitation details, tiering limitations, attack steps, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.