Jenkins
Jenkins Security Advisory 2019-08-07
2019-08-07 Aug 7, 2019 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2019-08-07/. 18 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2019-08-07/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
14 lines
Showing 1–14 of 14
CVE-2019-10373
BR2019-0000-019171
SECURITY-879
unclaimed
Stored XSS vulnerability in Build Pipeline Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-10381
BR2019-0000-019172
SECURITY-931
unclaimed
Codefresh Integration Plugin globally and unconditionally disables SSL/TLS certificate validation
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-10388
BR2019-0000-019173
SECURITY-1053
unclaimed
CSRF vulnerability and missing permission check in Relution Enterprise Appstore Publisher Plugin allow SSRF
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-10382
BR2019-0000-019174
SECURITY-1376
unclaimed
VMware Lab Manager Slaves Plugin globally and unconditionally disables SSL/TLS certificate validation
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-10378
BR2019-0000-019175
SECURITY-1428
unclaimed
TestLink Plugin stores credentials in plain text
Credited as David Fiser of Trend Micro Nebula working with Trend Micro's Zero Day Initiative
CVE-2019-10385
BR2019-0000-019176
SECURITY-1430
unclaimed
eggplant-plugin Plugin stores credentials in plain text
Credited as David Fiser of Trend Micro Nebula working with Trend Micro's Zero Day Initiative
CVE-2019-10380
BR2019-0000-019177
SECURITY-922
unclaimed
Script sandbox bypass vulnerability in Simple Travis Pipeline Runner Plugin
Credited as Jesse Glick, CloudBees, Inc.
CVE-2019-10376
BR2019-0000-019178
SECURITY-751
unclaimed
Reflected XSS vulnerability in Wall Display Master Project Plugin
Credited as MWR labs (@mwrlabs)
CVE-2019-10370
BR2019-0000-019179
SECURITY-157
unclaimed
Mask Passwords Plugin shows plain text passwords in global configuration form fields
Credited as Matthias Schmalz, SAP SE
CVE-2019-10386
BR2019-0000-019180
SECURITY-1008
unclaimed
CSRF vulnerability and missing permission check in XL TestView Plugin allow capturing credentials
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2019-10377
BR2019-0000-019181
SECURITY-1099
unclaimed
Avatar Plugin allows changing other users' avatars
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2019-10368
BR2019-0000-019182
SECURITY-1482
unclaimed
CSRF vulnerability and missing permission check in JClouds Plugin allowed capturing credentials
Credited as Oleg Nenashev, CloudBees, Inc., and, independently, Viktor Gazdag NCC Group
CVE-2019-10371
BR2019-0000-019183
SECURITY-795
unclaimed
HTTP session fixation vulnerability in GitLab Authentication Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2019-10372
BR2019-0000-019184
SECURITY-796
unclaimed
Open redirect vulnerability in GitLab Authentication Plugin
Credited as Wadeck Follonier, CloudBees, Inc.