Security vulnerability impacting DEV@cloud
Incident Report for CloudBees
Resolved
This incident has been resolved.
Posted Nov 12, 2016 - 16:52 UTC
Monitoring
The identified vulnerabilities are described in more detail here:

https://support.cloudbees.com/hc/en-us/articles/234805187-SECURITY-360-Advisory

https://jenkins.io/blog/2016/11/12/addressing-remote-vulnerabilities-in-cli/

We have updated configuration for DEV@Cloud customers to mitigate issues. The CLI and OPE features remain disabled for customers until Jenkins is restarted. If you would like to reactivate these features you can use the /restart URL on your Jenkins instance. Please contact Cloudbees Support for more information or further assistance.
Posted Nov 12, 2016 - 12:03 UTC
Identified
We have been made aware of a high impact security vulnerability that impacts our DEV@cloud environment.

We have disabled certain functionality as it relates to CLI and OPE features as our security team works on a formal mitigation.

All DEV@cloud customers are now protected from this vulnerability.

We will update this status site with further details as they become available.
Posted Nov 11, 2016 - 16:51 UTC