Jenkins Security Advisory 2023-09-06
Affects plugin: Assembla Auth Affects plugin: AWS CodeCommit Trigger Affects plugin: Bitbucket Push and Pull Request Affects plugin: Frugal Testing Affects plugin: Google Login Affects plugin: Ivy Affects plugin: Job Configuration History Affects plugin: Microsoft Entra ID (previously Azure AD) Affects plugin: Pipeline Maven Integration Affects plugin: Qualys Container Scanning Connector Affects plugin: SSH2 Easy Affects plugin: TAP
CSIRTS triage
- What
- Multiple plugins are affected by security vulnerabilities.
- Who is affected
- Users of affected Jenkins plugins.
- Urgency
- Remediation is urgent due to the potential for exploitation, but no specific exploits are reported.
- Action
- Update affected plugins as per the advisory.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.jenkins.io/security/advisory/2023-09-06/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2023-419300.76% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-419310.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-419320.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-419330.75% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-419340.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-419350.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-419360.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-419370.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-47770.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-467512.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] Apache Ivy: Vulnerability allows information disclosurecert-bund
- unknownJenkins Security Advisory 2024-11-13jenkins
More from Jenkins Security Advisories
- unknownJenkins Security Advisory 2026-08-052026-08-05
- unknownJenkins Security Advisory 2026-06-242026-06-24
- unknownJenkins Security Advisory 2026-06-102026-06-10
- unknownJenkins Security Advisory 2026-05-272026-05-27
- unknownJenkins Security Advisory 2026-04-292026-04-29