Skip to content

Commit

Permalink
Add 2024-03-20 security advisory
Browse files Browse the repository at this point in the history
  • Loading branch information
daniel-beck committed Mar 20, 2024
1 parent dfd96d4 commit 6ea537a
Show file tree
Hide file tree
Showing 3 changed files with 41 additions and 0 deletions.
5 changes: 5 additions & 0 deletions content/_data/changelogs/lts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10696,6 +10696,11 @@
- version: "2.440.2"
date: 2023-03-20
changes:
- type: security
message: Important security fix.
references:
- url: /security/advisory/2024-03-20/
title: security advisory
- type: rfe
category: rfe
pull: 8923
Expand Down
5 changes: 5 additions & 0 deletions content/_data/changelogs/weekly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22680,6 +22680,11 @@
- version: '2.444'
date: 2024-02-06
changes:
- type: security
message: Important security fix.
references:
- url: /security/advisory/2024-03-20/
title: 2024-03-20 security advisory
- type: rfe
category: rfe
pull: 8922
Expand Down
31 changes: 31 additions & 0 deletions content/security/advisory/2024-03-20.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
layout: advisory
title: Jenkins Security Advisory 2024-03-20
kind: core
core:
lts:
previous: 2.440.1
fixed: 2.440.2
weekly:
previous: '2.443'
fixed: '2.444'
issues:
- id: SECURITY-3379
title: HTTP/2 denial of service vulnerability in bundled Jetty
cve: CVE-2024-22201
cvss:
severity: High
vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
description: |-
Jenkins bundles Winstone-Jetty, a wrapper around Jetty, to act as HTTP and servlet server when started using `java -jar jenkins.war`.
This is how Jenkins is run when using any of the installers or packages, but not when run using servlet containers such as Tomcat.

Jenkins 2.443 and earlier, LTS 2.440.1 and earlier bundles versions of Jetty affected by the security vulnerability https://www.cve.org/CVERecord?id=CVE-2024-22201[CVE-2024-22201].
This vulnerability allows unauthenticated attackers to cause a denial of service.

NOTE: This only affects instances that enable HTTP/2, typically using the `--http2Port` argument to `java -jar jenkins.war` or corresponding options in service configuration files.
It is disabled by default in all native installers and the Docker images provided by the Jenkins project.

Jenkins 2.444, LTS 2.440.2 updates the bundled Jetty to version 10.0.20, which is unaffected by these issues.

Administrators unable to update to these releases of Jenkins (or newer) are advised to disable HTTP/2.

0 comments on commit 6ea537a

Please sign in to comment.