CloudBees Security Advisory 2022-01-28

This advisory announces vulnerabilities in CloudBees Jenkins Platform and CloudBees CI

Security vulnerability in the Kubernetes Client API plugin [CVE-2021-4178]

BEE-14547

A security vulnerability in the CloudBees CI user interface would allow an authorized user to enter YAML information that would be processed by the Kubernetes Client API plugin.

The Kubernetes Client API plugin has been updated to a version that is not affected by this vulnerability. This issue has been resolved.

Severity

Fix

  • CloudBees Traditional Platforms should be upgraded to 2.319.2.9

  • CloudBees Cloud Platforms should be upgraded to 2.319.2.9

  • CloudBees Jenkins Enterprise should be upgraded to 2.319.2.9 the Managed Masters and Operations Center

  • CloudBees Jenkins Platform (rolling train, CJP Operations Center and CJP Client Master (2.x.y.z)) should be upgraded to 2.319.2.9 version

  • CloudBees Jenkins Platform (fixed train, CJP Operations Center and CJP Client Master (2.303.x.0.z)) should be upgraded to 2.303.30.0.4 version