CloudBees Security Advisory 2023-05-03

This advisory announces vulnerabilities in CloudBees CI and CloudBees Jenkins Platform

Low-Privilege Users to Run Restores at Will

BEE-29577
Severity (CVSS): 
Medium
Affected plugins: infradna-backup
Description:

A user with Job/Configure privilege could restore backups when the lack of permissions should prevent it.

Backup Jobs Can Be Broken by Low-Privilege User With Job/Configure

BEE-29576
Severity (CVSS): 
Medium
Affected plugins: infradna-backup
Description:

A user with Job/Configure privilege could break backup jobs created by other users

Severity

Fix

  • CloudBees Traditional Platforms should be upgraded to 2.387.3.3

  • CloudBees Cloud Platforms should be upgraded to 2.387.3.3.

  • CloudBees Jenkins Platform (fixed train, CJP Operations Center and CJP Client Master (2.346.x.0.z)) should be upgraded to 2.346.40.0.16