Security advisory
Security advisory
-
CloudBees Security Advisory 2020-07-15
This advisory announces vulnerabilities in Jenkins, CloudBees Jenkins Distribution, CloudBees Jenkins Platform and CloudBees CI.
Plugin modifications
-
Jenkins LTS
Upgraded Jenkins LTS from
2.222.4-cb-1
to2.222.40-cb-3
-
Upgraded CloudBees Folders Plus Plugin from
3.9
to3.10
-
Upgraded Amazon EC2 Plugin from
1.50.2
to1.50.2.1
-
Upgraded External Notification Plugin from
1.2
to1.2.1
-
Upgraded Jackson2 API Plugin from
2.10.3
to2.11.0
-
Upgraded Matrix Authorization Strategy Plugin from
2.5
to2.5.1
-
Upgraded Matrix Project Plugin from
1.14
to1.14.1
-
Upgraded CloudBees Role-Based Access Control Plugin from
5.32
to5.32.1
-
Upgraded Script Security Plugin from
1.71
to1.73
Compatible plugins
-
Jenkins Apache HttpComponents Client 4.x API Plugin
4.5.10-2.0 compatible installed by default
-
1.11.723 compatible optional
-
1.19 compatible optional
-
Oracle Java SE Development Kit Installer Plugin
1.4 compatible installed by default
-
Jenkins Active Directory plugin
2.16 compatible optional
-
Jenkins Health Advisor by CloudBees
3.1.0 compatible optional
-
1.1.14 compatible optional
-
2.69 compatible optional
-
Matrix Authorization Strategy Plugin
2.5.1 compatible optional
-
1.50.2.1 compatible optional
-
4.2.0 compatible optional
-
2.68 compatible installed by default
-
1.5.0 compatible installed by default
-
Google OAuth Credentials plugin
1.0.0 compatible optional
-
Stack Trace Suppression Plugin
1.5 compatible optional
-
2.22 compatible installed by default
-
1.34 compatible optional
-
CloudBees AWS Credentials Plugin
1.28 compatible optional
-
0.4 compatible optional
-
1.0.5 compatible optional
-
Jenkins JSch dependency plugin
0.1.55.2 compatible optional
-
3.6 compatible optional
-
2.3.0.1 compatible installed by default
-
1.6 compatible optional
-
1.14.1 compatible optional
-
1.4 compatible installed by default
-
2.18 compatible installed by default
-
2.40 compatible installed by default
-
2.2.0 compatible optional
-
1.5.1 compatible optional
-
0.3.1 compatible optional
Proprietary plugins
-
Operations Center Server Plugin
2.222.0.9 proprietary installed by default
-
Operations Center Server Cluster Operations
2.222.0.2 proprietary optional
-
9.42 proprietary installed by default
-
Operations Center Notification
1.0 proprietary optional
-
1.2 proprietary optional
-
Operations Center Analytics Feeder
2.222.0.1 proprietary optional
-
User Activity Monitoring Plugin
1.1.5 proprietary optional
-
1.20 proprietary optional
-
Operations Center Server EC2 Cloud
2.222.0.2 proprietary optional
-
CloudBees Role-Based Access Control Plugin
5.32.1 proprietary optional
-
Operations Center Analytics Viewer
2.222.0.1 proprietary optional
-
2.222.0.1 proprietary optional
-
Operations Center Single Sign-On Plugin
2.222.0.3 proprietary optional
-
Operations Center Server Role Based Access Control
2.222.0.2 proprietary optional
-
CloudBees Update Center Plugin
4.47 proprietary optional
-
Operations Center Embedded elasticsearch
2.73.0.1 proprietary optional
-
CloudBees Administrative Monitors Plugin
1.0.1 proprietary installed by default
-
CloudBees Update Center Data API
4.43 proprietary installed by default
-
CloudBees VMWare Autoscaling Plugin
4.3.9 proprietary optional
-
Operations Center Server License Entitlement Check
2.222.0.2 proprietary installed by default
-
Operations Center Elasticsearch Provider
2.222.0.2 proprietary optional
-
3.10 proprietary installed by default
-
CloudBees CyberArk Credentials Provider Plugin
1.0.5 proprietary optional
-
1.10 proprietary optional
-
CloudBees Jenkins Enterprise License Entitlement Check
8.27 proprietary installed by default
-
Operations Center Monitoring Plugin
2.222.0.2 proprietary optional
-
2.9 proprietary installed by default
-
Operations Center Analytics Reporter
2.222.0.1 proprietary optional
-
Operations Center Update Center Plugin
2.222.0.2 proprietary optional
-
Operations Center Analytics Configuration
2.222.0.1 proprietary optional
-
2.222.0.4 proprietary installed by default
-
Operations Center Analytics Kibana Dashboards
2.222.0.1 proprietary optional
-
CloudBees Restart Aborted Builds Plugin
1.13 proprietary optional
-
Operations Center JNLP Agent Controller Plugin
2.222.0.3 proprietary optional
-
CloudBees WikiText Security Plugin
3.13 proprietary optional
-
Beekeeper Upgrade Assistant Plugin
2.138.0.13 proprietary installed by default
-
2.222.0.3 proprietary installed by default
-
3.22 proprietary installed by default
-
1.2.1 proprietary optional
-
3.38.18 proprietary optional
-
CloudBees SSH Build Agents Plugin
2.7 proprietary optional
-
1.16 proprietary installed by default
-
1.6 proprietary optional
-
CloudBees Skip Next Build Plugin
4.5 proprietary optional
Verified plugins
-
1.73 verified installed by default
-
2.3.7 verified installed by default
-
1.18.1 verified optional
-
1.23 verified optional
-
1.31 verified installed by default
-
1.0.9.0 verified installed by default
-
1.28 verified installed by default
-
2.3.2 verified installed by default
-
1.1.5 verified optional
-
4.0.2.6 verified installed by default
-
3.6.3 verified optional
-
1.20 verified installed by default
-
1.31.2 verified optional
-
1.3 verified installed by default
-
2.12 verified installed by default
-
2.6.3 verified installed by default
-
2.11.0 verified installed by default
-
1.24 verified optional
-
Secure Requester Whitelist Plugin
1.5 verified optional
-
1.5 verified optional
-
1.7.24.3 verified installed by default
-
Authentication Tokens API Plugin
1.3 verified optional
-
1.7 verified optional
-
2.0 verified optional
-
6.12 verified installed by default