Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Fedora 22 FEDORA-2015-5430 Moderate: Jenkins Executable War Security Fix

fedora
Calendar Grey April 21, 2015
Scroller Fedora
Enhance the security of Jenkins on Fedora 22 by addressing XSS, DoS, and directory traversal vulnerabilities through strategic input validation, rate limiting, and file path sanitization
Security fix for CVE-2015-1806, CVE-2015-1807, CVE-2015-1813, CVE-2015-1812, CVE-2015-1810, CVE-2015-1808, CVE-2015-1809, CVE-2015-1814, CVE-2015-1811

Summary

This package enables executable war support for Jenkins.

Update Information:

Security fix for CVE-2015-1806, CVE-2015-1807, CVE-2015-1813, CVE-2015-1812, CVE-2015-1810, CVE-2015-1808, CVE-2015-1809, CVE-2015-1814, CVE-2015-1811

Change Log

References


[ 1 ] Bug #1205615 - CVE-2015-1812 CVE-2015-1813 jenkins: Reflective XSS vulnerability (SECURITY-171, SECURITY-177) https://bugzilla.redhat.com/show_bug.cgi?id=1205615 [ 2 ] Bug #1205620 - CVE-2015-1806 jenkins: Combination filter Groovy script unsecured (SECURITY-125) https://bugzilla.redhat.com/show_bug.cgi?id=1205620 [ 3 ] Bug #1205623 - CVE-2015-1808 jenkins: update center metadata retrieval DoS attack (SECURITY-163) https://bugzilla.redhat.com/show_bug.cgi?id=1205623 [ 4 ] Bug #1205627 - CVE-2015-1810 jenkins: HudsonPrivateSecurityRealm allows creation of reserved names (SECURITY-166) https://bugzilla.redhat.com/show_bug.cgi?id=1205627 [ 5 ] Bug #1205616 - CVE-2015-1814 jenkins: forced API token change (SECURITY-180) https://bugzilla.redhat.com/show_bug.cgi?id=1205616 [ 6 ] Bug #1205622 - CVE-2015-1807 jenkins: directory traversal from artifacts via symlink (SECURITY-162) https://bugzilla.redhat.com/show_bug.cgi?id=120...

Read the Full Advisory

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update jenkins-executable-war' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: jenkins-executable-war
Product: Fedora 22
Version: 1.29
Release: 4.fc22
Summary: Jenkins Executable War

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.