Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2019-10-23

2019-10-23 Oct 23, 2019 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2019-10-23/. 9 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2019-10-23/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

9 lines
Showing 1–9 of 9
CVE-2019-10460 BR2019-0000-015549 SECURITY-1546 unclaimed
Bitbucket OAuth Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-10467 BR2019-0000-015550 SECURITY-1003 unclaimed
Sonar Gerrit Plugin stored credentials in plain text
Credited as Oleg Nenashev, CloudBees, Inc.
Acknowledgement BR2019-0000-015551 SECURITY-1005 unclaimed
SECURITY-1005
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2019-10474 BR2019-0000-015552 SECURITY-1073 unclaimed
Missing permission check in Global Post Script Plugin allowed obtaining configuration data
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2019-10464 BR2019-0000-015553 SECURITY-820 unclaimed
CSRF vulnerability and missing permission check in Deploy WebLogic Plugin
Credited as Thomas de Grenier de Latour
CVE-2019-10466 BR2019-0000-015554 SECURITY-822 unclaimed
XXE vulnerability in fireline Plugin
Credited as Thomas de Grenier de Latour
CVE-2019-10461 BR2019-0000-015555 SECURITY-1477 unclaimed
Dynatrace Application Monitoring Plugin stored credentials in plain text
Credited as Viktor Gazdag NCC Group
Acknowledgement BR2019-0000-015556 SECURITY-1483 unclaimed
SECURITY-1483
Credited as Viktor Gazdag NCC Group
CVE-2019-10475 BR2019-0000-015557 SECURITY-1490 unclaimed
Reflected XSS vulnerability in build-metrics Plugin
Credited as Viktor Gazdag NCC Group