Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2019-09-12

2019-09-12 Sep 12, 2019 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2019-09-12/. 6 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2019-09-12/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

6 lines
Showing 1–6 of 6
CVE-2019-10392 BR2019-0000-019157 SECURITY-1534 unclaimed
System command execution vulnerability in Git client Plugin
Credited as Francesco Soncina - ABN AMRO Red Team - https://iwantmore.pizza
CVE-2019-10397 BR2019-0000-019158 SECURITY-1509 unclaimed
Aqua Security Serverless Scanner Plugin showed plain text password in job configuration form fields
Credited as James Holderness, IB Boost
CVE-2019-10398 BR2019-0000-019159 SECURITY-1545 unclaimed
Beaker builder Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10393 BR2019-0000-019160 SECURITY-1538 unclaimed
Sandbox bypass vulnerability in Script Security Plugin
Credited as Nils Emmerich of ERNW Research GmbH
CVE-2019-10395 BR2019-0000-019161 SECURITY-1476 unclaimed
Stored XSS vulnerability in Build Environment Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-10396 BR2019-0000-019162 SECURITY-1489 unclaimed
Stored XSS vulnerability in Dashboard View Plugin
Credited as Viktor Gazdag NCC Group