Jenkins Multiple Vulnerabilities
Release Date: 17 Jun 2026
RISK: Medium Risk
TYPE: Servers - Internet App Servers
Multiple vulnerabilities were identified in Jenkins. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, spoofing, security restriction bypass, sensitive information disclosure and cross-site scripting on the targeted system.
Impact
- Remote Code Execution
- Cross-Site Scripting
- Spoofing
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Jenkins weekly 2.567 and earlier versions
- Jenkins LTS 2.555.2 and earlier versions
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2026-53435
- CVE-2026-53436
- CVE-2026-53437
- CVE-2026-53438
- CVE-2026-53439
- CVE-2026-53440
- CVE-2026-53441
- CVE-2026-53442
沒有留言:
發佈留言