Skip to content

Jenkins

vjenkins-2.572 scope: jenkins Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 19d Pipelines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ci-cd devops groovy java jenkins pipelines-as-code

Affected surfaces

rce_ssrf

Summary

AI summary

Updates 🐛 Bug fixes, https://issue-redirect.jenkins.io/issue/69789, and https://github.com/apps/renovate across a mixed release.

Full changelog

This is an automatically generated changelog draft for Jenkins weekly releases.
See https://www.jenkins.io/changelog/2.572/ for the official changelog for this release.

🚀 New features and improvements

  • JENKINS-69789 - Add password complexity rule extension point (#26774) @cytrock
  • Refine borders across Jenkins UI (#26974) @janfaracik
  • Restrict elements in PersistedList and COWL on deserialization (#26918) @daniel-beck
  • Prohibit deserialization of Object fields by default (#26915) @daniel-beck
  • Make Nodes page wide in experimental Manage Jenkins UI (#26997) @janfaracik
  • Refine Notifications component (#27005) @janfaracik

🐛 Bug fixes

  • Keep modal dialogs fixed to the viewport (#27028) @oleksii-tumanov
  • Fix Plugin Manager links without wiki URL (#26976) @oleksii-tumanov

All contributors: @cytrock, @daniel-beck, @janfaracik, @oleksii-tumanov, @renovate[bot] and renovate[bot]

Security Fixes

  • Restrict elements in PersistedList and COWL on deserialization (#26918) @daniel-beck
  • Prohibit deserialization of Object fields by default (#26915) @daniel-beck

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Jenkins

Get notified when new releases ship.

Sign up free

About Jenkins

Jenkins automation server

All releases →

Related context

Beta — feedback welcome: [email protected]