Jenkins
Jenkins Security Advisory 2019-10-23
2019-10-23 Oct 23, 2019 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2019-10-23/. 9 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2019-10-23/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
9 lines
Showing 1–9 of 9
CVE-2019-10460
BR2019-0000-015549
SECURITY-1546
unclaimed
Bitbucket OAuth Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10467
BR2019-0000-015550
SECURITY-1003
unclaimed
Sonar Gerrit Plugin stored credentials in plain text
Credited as Oleg Nenashev, CloudBees, Inc.
Acknowledgement
BR2019-0000-015551
SECURITY-1005
unclaimed
SECURITY-1005
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2019-10474
BR2019-0000-015552
SECURITY-1073
unclaimed
Missing permission check in Global Post Script Plugin allowed obtaining configuration data
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2019-10464
BR2019-0000-015553
SECURITY-820
unclaimed
CSRF vulnerability and missing permission check in Deploy WebLogic Plugin
Credited as Thomas de Grenier de Latour
CVE-2019-10466
BR2019-0000-015554
SECURITY-822
unclaimed
XXE vulnerability in fireline Plugin
Credited as Thomas de Grenier de Latour
CVE-2019-10461
BR2019-0000-015555
SECURITY-1477
unclaimed
Dynatrace Application Monitoring Plugin stored credentials in plain text
Credited as Viktor Gazdag NCC Group
Acknowledgement
BR2019-0000-015556
SECURITY-1483
unclaimed
SECURITY-1483
Credited as Viktor Gazdag NCC Group
CVE-2019-10475
BR2019-0000-015557
SECURITY-1490
unclaimed
Reflected XSS vulnerability in build-metrics Plugin
Credited as Viktor Gazdag NCC Group