Jenkins
Jenkins Security Advisory 2019-09-25
2019-09-25 Sep 25, 2019 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2019-09-25/. 24 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2019-09-25/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
27 lines
Showing 1–27 of 27
CVE-2019-10408
BR2019-0000-019130
SECURITY-401
unclaimed
CSRF vulnerability and missing permission check in Project Inheritance Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-10427
BR2019-0000-019131
SECURITY-1507
unclaimed
Aqua MicroScanner Plugin showed plain text credential in configuration form
Credited as James Holderness, IB Boost
CVE-2019-10428
BR2019-0000-019132
SECURITY-1508
unclaimed
Aqua Security Scanner Plugin showed plain text password in configuration form
Credited as James Holderness, IB Boost
CVE-2019-10411
BR2019-0000-019133
SECURITY-1513
unclaimed
Inedo BuildMaster Plugin Plugin showed plain text password in configuration form
Credited as James Holderness, IB Boost
CVE-2019-10412
BR2019-0000-019134
SECURITY-1514
unclaimed
Inedo ProGet Plugin Plugin showed plain text password in configuration form
Credited as James Holderness, IB Boost
CVE-2019-10419
BR2019-0000-019135
SECURITY-1541
unclaimed
vFabric Application Director Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10420
BR2019-0000-019136
SECURITY-1543
unclaimed
Assembla Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10421
BR2019-0000-019137
SECURITY-1544
unclaimed
Azure Event Grid Build Notifier Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10422
BR2019-0000-019138
SECURITY-1548
unclaimed
Call Remote Job Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10423
BR2019-0000-019139
SECURITY-1551
unclaimed
CodeScan Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10413
BR2019-0000-019140
SECURITY-1557
unclaimed
Data Theorem Mobile Security: CI/CD Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10424
BR2019-0000-019141
SECURITY-1561
unclaimed
elOyente Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10425
BR2019-0000-019142
SECURITY-1572
unclaimed
Google Calendar Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10426
BR2019-0000-019143
SECURITY-1573
unclaimed
Gem Publisher Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10414
BR2019-0000-019144
SECURITY-1574
unclaimed
Git Changelog Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10429
BR2019-0000-019145
SECURITY-1575
unclaimed
GitLab Logo Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10415
BR2019-0000-019146
SECURITY-1577
unclaimed
Violation Comments to GitLab Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
Acknowledgement
BR2019-0000-019147
SECURITY-920
unclaimed
SECURITY-920
Credited as Jesse Glick, CloudBees, Inc.
CVE-2019-10405
BR2019-0000-019148
SECURITY-1505
unclaimed
Diagnostic web page exposed Cookie HTTP header
Credited as Jonathan Leitschuh
CVE-2019-10406
BR2019-0000-019149
SECURITY-1471
unclaimed
XSS vulnerability in Jenkins URL setting
Credited as Katherine Hough
CVE-2019-10406
BR2019-0000-019150
SECURITY-1471
unclaimed
XSS vulnerability in Jenkins URL setting
Credited as Jonathan Bell
CVE-2019-10401
BR2019-0000-019151
SECURITY-1498
unclaimed
Stored XSS vulnerability in expandable textbox form control
Credited as Matt Sicker, CloudBees Inc.
CVE-2019-10401
BR2019-0000-019152
SECURITY-1498
unclaimed
Stored XSS vulnerability in expandable textbox form control
Credited as Wadeck Follonier, CloudBees Inc.
CVE-2019-10402
BR2019-0000-019153
SECURITY-1525
unclaimed
XSS vulnerability in combobox form control
Credited as Matt Sicker, CloudBees Inc.
CVE-2019-10402
BR2019-0000-019154
SECURITY-1525
unclaimed
XSS vulnerability in combobox form control
Credited as Wadeck Follonier, CloudBees Inc.
CVE-2019-10410
BR2019-0000-019155
SECURITY-732
unclaimed
Stored XSS vulnerability in Log Parser Plugin
Credited as Oleg Nenashev, CloudBees, Inc.
Acknowledgement
BR2019-0000-019156
SECURITY-1537
unclaimed
SECURITY-1537
Credited as Wadeck Follonier, CloudBees, Inc.