Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Jenkins plugins security advisory 2023-01-24 #3158

Closed
richardlau opened this issue Jan 25, 2023 · 2 comments
Closed

Jenkins plugins security advisory 2023-01-24 #3158

richardlau opened this issue Jan 25, 2023 · 2 comments

Comments

@richardlau
Copy link
Member

The following Jenkins plugin updates contain fixes for security vulnerabilities:

  • Azure AD Plugin 306.va_7083923fd50
  • Bitbucket OAuth Plugin 0.13
  • Gerrit Trigger Plugin 2.38.1
  • Kubernetes Credentials Provider Plugin 1.209.v862c6e5fb_1ef
  • OpenId Connect Authentication Plugin 2.5
  • Orka by MacStadium Plugin 1.32
  • Script Security Plugin 1229.v4880b_b_e905a_6
  • Semantic Versioning Plugin 1.15

Additionally, we announce unresolved security issues in the following plugins:

  • BearyChat Plugin
  • Cisco Spark Notifier Plugin
  • GitHub Pull Request Builder Plugin
  • GitHub Pull Request Coverage Status Plugin
  • JIRA Pipeline Steps Plugin
  • Keycloak Authentication Plugin
  • MSTest Plugin
  • OpenID Plugin
  • PWauth Security Realm Plugin
  • RabbitMQ Consumer Plugin
  • TestComplete support Plugin
  • TestQuality Updater Plugin
  • view-cloner Plugin
  • visualexpert Plugin

Please see the advisory for more information:
https://www.jenkins.io/security/advisory/2023-01-24/

@richardlau
Copy link
Member Author

Of these we're only using the Script Security Plugin. I've updated it on both the test and release servers.
The test CI server has been restarted.
Release CI will restart when current builds have completed.

@richardlau
Copy link
Member Author

FWIW we had to revert the update of this plugin: #3159
Plan is to update it again when we update Jenkins to the current LTS version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant