Commons compress [CVE-2021-35517]
BEE-8404
A malicious user could inject a crafted tar file that may impact the availability of the instance, even reaching an OOM (out of memory error).
The library has been updated in Jenkins core to fix this issue.
JSoup vulnerability CVE-2021-37714 in cloudbees-update-center-plugin
BEE-8837
cloudbees-update-center-plugin v4.64 and previous version contains a vulnerable version of JSoup (CVE-2021-37714).
cloudbees-update-center-plugin has been updated to update JSoup to remove such a vulnerability.