ZeroHour
Jenkins Security Advisoriespublished ()ingested 1

Jenkins Security Advisory 2026-09-02

lowAdvisoryimportance 25
AI summary · glm-5.3-flash

Jenkins releases a security advisory affecting Jenkins Core, update-center2, and 17 plugins including GitLab, SAML, LDAP, Microsoft Entra ID, and Script Security.

Jenkins published its September 2, 2026 security advisory covering Jenkins Core, the update-center2 tool, and 17 plugins, including widely deployed ones such as GitLab, SAML, LDAP, Microsoft Entra ID, Script Security, SonarQube Scanner, and Pipeline: Groovy Libraries. The announcement text does not include CVE identifiers, affected version ranges, or any statement about active exploitation. Jenkins plugin advisories typically bundle fixes for issues like stored XSS, CSRF, and missing permission checks. Administrators running any of the listed components should update them via the Jenkins update center.

  • Advisory spans Jenkins Core, update-center2, and 17 plugins.
  • Affected plugins include GitLab, SAML, LDAP, and Microsoft Entra ID.
  • No CVE identifiers or exploitation details appear in the announcement text.
  • Administrators should update affected components through the Jenkins update center.
Full article

Affects Jenkins Core Affects plugin: Allure Affects plugin: Customizable Header Affects plugin: File Parameter Affects plugin: GitLab Affects plugin: Job Configuration History Affects plugin: LDAP Affects plugin: Microsoft Entra ID (previously Azure AD) Affects plugin: Parameterized Remote Trigger Affects plugin: Performance Affects plugin: Pipeline: Build Step Affects plugin: Pipeline: Groovy Libraries Affects plugin: SAML Affects plugin: Script Security Affects plugin: SonarQube Scanner Affects plugin: ThinBackup Affects plugin: TICS Affects plugin: XebiaLabs XL Deploy Affects update-center2

This source does not provide full text. Read it at jenkins.io.