Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2020-01-15

2020-01-15 Jan 15, 2020 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-01-15/. 6 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2020-01-15/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

5 lines
Showing 1–5 of 5
CVE-2020-2096 BR2020-0000-015503 SECURITY-1683 unclaimed
Reflected XSS vulnerability in gitlab-hook Plugin
Credited as Ai Ho (@j3ssiejjj)
CVE-2020-2092 BR2020-0000-015504 SECURITY-1698 unclaimed
XXE vulnerability in Robot Framework Plugin
Credited as Federico Pellegrin
CVE-2020-2090 BR2020-0000-015505 SECURITY-1004 unclaimed
CSRF vulnerability and missing permission checks in Amazon EC2 Plugin
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2020-2097 BR2020-0000-015506 SECURITY-814 unclaimed
CSRF vulnerability and missing permission checks in Sounds Plugin allow OS command execution
Credited as Thomas de Grenier de Latour
CVE-2020-2095 BR2020-0000-015507 SECURITY-1696 unclaimed
Redgate SQL Change Automation Plugin stored credentials in plain text
Credited as Wadeck Follonier, CloudBees, Inc.