Jenkins
Jenkins Security Advisory 2019-12-17
2019-12-17 Dec 17, 2019 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2019-12-17/. 17 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2019-12-17/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
18 lines
Showing 1–17 of 17 matching · clear filters
CVE-2019-16551
BR2019-0000-015508
SECURITY-1527
unclaimed
CSRF vulnerability and missing permission checks in Gerrit Trigger Plugin
Credited as Alex Earl (@alexcearl), Marvell Semiconductor, Inc.
CVE-2019-16549
BR2019-0000-015509
SECURITY-1681
unclaimed
XXE vulnerability in Maven Release Plug-in Plugin
Credited as Cheng Gao, Alibaba Cloud Intelligence Security Team, https://www.aliyun.com/
CVE-2019-16559
BR2019-0000-015510
SECURITY-1371
unclaimed
CSRF vulnerability and missing permission checks in WebSphere Deployer Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-16558
BR2019-0000-015511
SECURITY-1580
unclaimed
SSL/TLS certificate validation globally and unconditionally disabled by Spira Importer Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-16561
BR2019-0000-015512
SECURITY-1581
unclaimed
SSL/TLS certificate validation globally and unconditionally disabled by WebSphere Deployer Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-16553
BR2019-0000-015513
SECURITY-1651
unclaimed
CSRF vulnerability and missing permission check in Build Failure Analyzer Plugin allow ReDoS
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-16568
BR2019-0000-015514
SECURITY-1521
unclaimed
SCTMExecutor Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-16562
BR2019-0000-015515
SECURITY-1591
unclaimed
Stored XSS vulnerability in buildgraph-view Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16563
BR2019-0000-015516
SECURITY-1592
unclaimed
Stored XSS vulnerability in Mission Control Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16564
BR2019-0000-015517
SECURITY-1593
unclaimed
Stored XSS vulnerability in Pipeline Aggregator View Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16572
BR2019-0000-015518
SECURITY-1597
unclaimed
Weibo Plugin stores credentials in plain text
Credited as Viktor Gazdag NCC Group
CVE-2019-16557
BR2019-0000-015519
SECURITY-1598
unclaimed
Redgate SQL Change Automation Plugin stores credentials in plain text
Credited as Viktor Gazdag NCC Group
CVE-2019-16573
BR2019-0000-015520
SECURITY-1600
unclaimed
CSRF vulnerability and missing permission checks in Alauda DevOps Pipeline Plugin allows capturing credentials
Credited as Viktor Gazdag NCC Group
CVE-2019-16575
BR2019-0000-015521
SECURITY-1602
unclaimed
CSRF vulnerability in Alauda Kubernetes Suport Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16569
BR2019-0000-015522
SECURITY-1603
unclaimed
CSRF vulnerability in Mantis Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16570
BR2019-0000-015523
SECURITY-1604
unclaimed
CSRF vulnerability and missing permission checks in RapidDeploy Plugin allow SSRF
Credited as Viktor Gazdag NCC Group
CVE-2019-16556
BR2019-0000-015525
SECURITY-1636
unclaimed
Rundeck Plugin stored credentials in plain text
Credited as Wadeck Follonier, CloudBees, Inc.