Jenkins
Jenkins Security Advisory 2020-01-15
2020-01-15 Jan 15, 2020 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-01-15/. 6 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2020-01-15/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
5 lines
Showing 1–5 of 5
CVE-2020-2096
BR2020-0000-015503
SECURITY-1683
unclaimed
Reflected XSS vulnerability in gitlab-hook Plugin
Credited as Ai Ho (@j3ssiejjj)
CVE-2020-2092
BR2020-0000-015504
SECURITY-1698
unclaimed
XXE vulnerability in Robot Framework Plugin
Credited as Federico Pellegrin
CVE-2020-2090
BR2020-0000-015505
SECURITY-1004
unclaimed
CSRF vulnerability and missing permission checks in Amazon EC2 Plugin
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2020-2097
BR2020-0000-015506
SECURITY-814
unclaimed
CSRF vulnerability and missing permission checks in Sounds Plugin allow OS command execution
Credited as Thomas de Grenier de Latour
CVE-2020-2095
BR2020-0000-015507
SECURITY-1696
unclaimed
Redgate SQL Change Automation Plugin stored credentials in plain text
Credited as Wadeck Follonier, CloudBees, Inc.