Hello All,
A recent CVE was published for the BlueOcean plugin being vulnerable to a
low effort CSRF attack that could disclose github credentials[1]
I have redeployed all Jenkins servers with an updated docker images that
contains a fixed version of BlueOcean.
The changes were minimal and should not be disruptive, but please let me
know if you experience any problems.
[1] https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3116
Regards,
--
Kelley Spoon <kelley.spoon(a)linaro.org>
Hello All;
FYI; the Cambridge lab took a serious power hit and is down. They are
scrambling to get things back up, but it may take all weekend.
Expect LAVA failures and other strange results.
Thanks;
-g
--
Linaro <http://www.linaro.org>
Glen Valante | /Director Program & Project Management/
T: +1.508.517.3461 <tel:1617-320-5000>
glen.valante(a)linaro.org <mailto:glen.valante@linaro.org> | Skype:
gvalante <callto:gvalante>