Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins to version 2.275Upgrade Jenkins LTS to version 2.263.2 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade python-keystoneauth1Upgrade haproxyUpgrade ignitionUpgrade ironic-images-ipa-ppc64leUpgrade python-oslo-contextUpgrade console-login-helper-messagesUpgrade conmonUpgrade python-oslo-utilsUpgrade python-stevedoreUpgrade jenkins-2-pluginsUpgrade python-pyrsistentUpgrade toolboxUpgrade python-sushyUpgrade ironic-images-ipa-x86_64Upgrade python-openstacksdkUpgrade butaneUpgrade jenkinsUpgrade openshift-clientsUpgrade rust-afterburnUpgrade python-sushy-oem-idracUpgrade python-oslo-dbUpgrade cri-toolsUpgrade python-oslo-policyUpgrade cri-oUpgrade openshiftUpgrade podmanUpgrade python-jsonschemaUpgrade redhat-release-coreosUpgrade openshift-ansibleUpgrade rteval-loadsUpgrade python-toozUpgrade python-debtcollectorUpgrade python-hardwareUpgrade python-oslo-i18nUpgrade atomic-openshift-service-idlerUpgrade ironic-imagesUpgrade openstack-ironic-python-agentUpgrade machine-config-daemonUpgrade openstack-ironicUpgrade python-openshiftUpgrade coreos-installerUpgrade python-oslo-configUpgrade python-ironic-libUpgrade openstack-ironic-inspectorUpgrade openvswitch2.15Upgrade python-eventletUpgrade python-oslo-serviceUpgrade python-oslo-concurrencyUpgrade python-oslo-serializationUpgrade runcUpgrade python-oslo-logUpgrade python-oslo-upgradecheckUpgrade ovn2.13Upgrade kata-containersUpgrade ostreeUpgrade python-ironic-prometheus-exporterUpgrade openshift-kuryrUpgrade python-kubernetes | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub