CloudBees Security Advisory 2020-11-19

This advisory announces vulnerabilities in CloudBees Jenkins Distribution, CloudBees Jenkins Platform and CloudBees CI

Groups on items and nodes are ignored after the RBAC migration until the next restart

CTR-2757

Groups on items and nodes are ignored after the RBAC migration until the next restart

Groups are not available on items after the RBAC migration until the next restart. Customers will either experience a lack of permissions or an increase depending on the their permission configuration strategy (either adding more permissions in folders or to filter roles)

Severity

Fix

  • CloudBees Traditional Platforms should be upgraded 2.249.3.3

  • CloudBees Cloud Platforms should be upgraded 2.249.3.3

  • CloudBees Jenkins Enterprise should be upgraded the Managed Masters and Operations Center to 2.249.3.3

  • CloudBees Jenkins Platform (rolling train, CJP Operations Center and CJP Client Master (2.x.y.z) should be upgraded to version 2.249.3.3

  • CloudBees Jenkins Platform (fixed train, CJP Operations Center and CJP Client Master (2.222.x.0.z) should be upgraded to version 2.222.42.0.2

  • CloudBees Jenkins Platform (fixed train, CJP Operations Center and CJP Client Master (2.190.x.0.z) should be upgraded to version 2.190.33.0.3