CloudBees Security Advisory 2021-08-25

This advisory announces vulnerabilities in Cloudbees and CloudBees Jenkins Platform

LDAP changes should be reflected when using RBAC

BEE-5618

LDAP permissions were not updated until Jenkins was restarted: when you use LDAP to grant users new permissions in RBAC, the changes are not effective until you restart Jenkins.

Permissions are now updated in RBAC without having to restart Jenkins.

Severity

Fix

  • CloudBees Traditional Platforms should be upgraded to 2.303.1.5

  • CloudBees Cloud Platforms should be upgraded to 2.303.1.5

  • CloudBees Jenkins Enterprise should be upgraded to 2.303.1.5 the Managed Masters and Operations Center

  • CloudBees Jenkins Platform (rolling train, CJP Operations Center and CJP Client Master (2.x.y.z)) should be upgraded to 2.303.1.5 version

  • CloudBees Jenkins Platform (fixed train, CJP Operations Center and CJP Client Master (2.277.x.0.z)) should be upgraded to 2.277.41.0.1 version

  • CloudBees Jenkins Platform (fixed train, CJP Operations Center and CJP Client Master (2.249.x.0.z)) should be upgraded to 2.249.32.0.1 version