CloudBees Security Advisory 2022-01-28
This advisory announces vulnerabilities in CloudBees Jenkins Platform and CloudBees CI
Security vulnerability in the Kubernetes Client API plugin [CVE-2021-4178]
BEE-14547
A security vulnerability in the CloudBees CI user interface would allow an authorized user to enter YAML information that would be processed by the Kubernetes Client API plugin.
The Kubernetes Client API plugin has been updated to a version that is not affected by this vulnerability. This issue has been resolved.
Severity
BEE-14547: Medium
Fix
CloudBees Traditional Platforms should be upgraded to 2.319.2.9
CloudBees Cloud Platforms should be upgraded to 2.319.2.9
CloudBees Jenkins Enterprise should be upgraded to 2.319.2.9 the Managed Masters and Operations Center
CloudBees Jenkins Platform (rolling train, CJP Operations Center and CJP Client Master (2.x.y.z)) should be upgraded to 2.319.2.9 version
CloudBees Jenkins Platform (fixed train, CJP Operations Center and CJP Client Master (2.303.x.0.z)) should be upgraded to 2.303.30.0.4 version