Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2019-12-17

2019-12-17 Dec 17, 2019 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2019-12-17/. 17 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2019-12-17/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

18 lines
Showing 1–17 of 17 matching · clear filters
CVE-2019-16551 BR2019-0000-015508 SECURITY-1527 unclaimed
CSRF vulnerability and missing permission checks in Gerrit Trigger Plugin
Credited as Alex Earl (@alexcearl), Marvell Semiconductor, Inc.
CVE-2019-16549 BR2019-0000-015509 SECURITY-1681 unclaimed
XXE vulnerability in Maven Release Plug-in Plugin
Credited as Cheng Gao, Alibaba Cloud Intelligence Security Team, https://www.aliyun.com/
CVE-2019-16559 BR2019-0000-015510 SECURITY-1371 unclaimed
CSRF vulnerability and missing permission checks in WebSphere Deployer Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-16558 BR2019-0000-015511 SECURITY-1580 unclaimed
SSL/TLS certificate validation globally and unconditionally disabled by Spira Importer Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-16561 BR2019-0000-015512 SECURITY-1581 unclaimed
SSL/TLS certificate validation globally and unconditionally disabled by WebSphere Deployer Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-16553 BR2019-0000-015513 SECURITY-1651 unclaimed
CSRF vulnerability and missing permission check in Build Failure Analyzer Plugin allow ReDoS
Credited as Daniel Beck, CloudBees, Inc.
CVE-2019-16568 BR2019-0000-015514 SECURITY-1521 unclaimed
SCTMExecutor Plugin stores credentials in plain text
Credited as James Holderness, IB Boost
CVE-2019-16562 BR2019-0000-015515 SECURITY-1591 unclaimed
Stored XSS vulnerability in buildgraph-view Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16563 BR2019-0000-015516 SECURITY-1592 unclaimed
Stored XSS vulnerability in Mission Control Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16564 BR2019-0000-015517 SECURITY-1593 unclaimed
Stored XSS vulnerability in Pipeline Aggregator View Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16572 BR2019-0000-015518 SECURITY-1597 unclaimed
Weibo Plugin stores credentials in plain text
Credited as Viktor Gazdag NCC Group
CVE-2019-16557 BR2019-0000-015519 SECURITY-1598 unclaimed
Redgate SQL Change Automation Plugin stores credentials in plain text
Credited as Viktor Gazdag NCC Group
CVE-2019-16573 BR2019-0000-015520 SECURITY-1600 unclaimed
CSRF vulnerability and missing permission checks in Alauda DevOps Pipeline Plugin allows capturing credentials
Credited as Viktor Gazdag NCC Group
CVE-2019-16575 BR2019-0000-015521 SECURITY-1602 unclaimed
CSRF vulnerability in Alauda Kubernetes Suport Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16569 BR2019-0000-015522 SECURITY-1603 unclaimed
CSRF vulnerability in Mantis Plugin
Credited as Viktor Gazdag NCC Group
CVE-2019-16570 BR2019-0000-015523 SECURITY-1604 unclaimed
CSRF vulnerability and missing permission checks in RapidDeploy Plugin allow SSRF
Credited as Viktor Gazdag NCC Group
CVE-2019-16556 BR2019-0000-015525 SECURITY-1636 unclaimed
Rundeck Plugin stored credentials in plain text
Credited as Wadeck Follonier, CloudBees, Inc.