Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.275Upgrade Jenkins LTS to version 2.263.2 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade python-oslo-utilsUpgrade redhat-release-coreosUpgrade openshiftUpgrade conmonUpgrade python-keystoneauth1Upgrade jenkins-2-pluginsUpgrade butaneUpgrade python-oslo-contextUpgrade python-pyrsistentUpgrade python-stevedoreUpgrade cri-oUpgrade python-oslo-policyUpgrade rteval-loadsUpgrade ignitionUpgrade python-debtcollectorUpgrade python-jsonschemaUpgrade toolboxUpgrade openshift-clientsUpgrade rust-afterburnUpgrade python-sushy-oem-idracUpgrade python-openstacksdkUpgrade python-toozUpgrade python-oslo-dbUpgrade console-login-helper-messagesUpgrade haproxyUpgrade ironic-images-ipa-ppc64leUpgrade cri-toolsUpgrade ironic-images-ipa-x86_64Upgrade openshift-ansibleUpgrade jenkinsUpgrade python-sushyUpgrade podmanUpgrade openstack-ironic-python-agentUpgrade runcUpgrade python-oslo-serviceUpgrade python-oslo-configUpgrade openstack-ironicUpgrade ovn2.13Upgrade atomic-openshift-service-idlerUpgrade python-ironic-prometheus-exporterUpgrade kata-containersUpgrade python-oslo-logUpgrade python-eventletUpgrade python-oslo-concurrencyUpgrade python-openshiftUpgrade coreos-installerUpgrade openshift-kuryrUpgrade python-hardwareUpgrade python-oslo-i18nUpgrade machine-config-daemonUpgrade python-oslo-serializationUpgrade python-oslo-upgradecheckUpgrade openstack-ironic-inspectorUpgrade python-kubernetesUpgrade ironic-imagesUpgrade openvswitch2.15Upgrade ostreeUpgrade python-ironic-lib | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub