Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities HKCERT

Jenkins Multiple Vulnerabilities

Multiple vulnerabilities in Jenkins, including spoofing, data manipulation, and remote code execution flaws, could allow an attacker to bypass security restrictions and elevate privileges on the targeted system. Affected versions include Jenkins weekly 2.554 and earlier, and Jenkins LTS 2.541.2 and earlier. The vendor has released fixes detailed in their advisory; administrators must apply the patches provided at the specified URL.
Read Full Article →

Multiple vulnerabilities were identified in Jenkins. An attacker could exploit some of these vulnerabilities to trigger spoofing, data manipulation, remote code execution, security restriction bypass and elevation of privilege on the targeted system. Impact Spoofing Remote Code Execution Elevation of Privilege Data Manipulation Security Restriction Bypass System / Technologies affected Jenkins weekly 2.554 and earlier versions Jenkins LTS 2.541.2 and earlier versions Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://www.jenkins.io/security/advisory/2026-03-18/

Share this article