Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2020-01-29

2020-01-29 Jan 29, 2020 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-01-29/. 10 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2020-01-29/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

11 lines
Showing 1–11 of 11
CVE-2020-2100 BR2020-0000-015458 SECURITY-1641 unclaimed
Jenkins vulnerable to UDP amplification reflection attack
Credited as Adam Thorn, University of Cambridge
CVE-2020-2108 BR2020-0000-015459 SECURITY-1719 unclaimed
XXE vulnerability in WebSphere Deployer Plugin
Credited as Cheng Gao, Alibaba Cloud Intelligence Security Team, https://www.aliyun.com/
CVE-2020-2104 BR2020-0000-015460 SECURITY-1650 unclaimed
Memory usage graphs accessible to anyone with Overall/Read
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2102 BR2020-0000-015461 SECURITY-1660 unclaimed
Non-constant time HMAC comparison
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2103 BR2020-0000-015462 SECURITY-1695 unclaimed
Diagnostic page exposed session cookies
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2103 BR2020-0000-015463 SECURITY-1695 unclaimed
Diagnostic page exposed session cookies
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2106 BR2020-0000-015464 SECURITY-1680 unclaimed
Stored XSS vulnerability in Code Coverage Plugin
Credited as Federico Pellegrin
CVE-2020-2107 BR2020-0000-015465 SECURITY-1565 unclaimed
Fortify Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
CVE-2020-2101 BR2020-0000-015466 SECURITY-1659 unclaimed
Non-constant time comparison of inbound TCP agent connection secret
Credited as Jesse Glick, CloudBees, Inc.
CVE-2020-2105 BR2020-0000-015467 SECURITY-1704 unclaimed
Jenkins REST APIs vulnerable to clickjacking
Credited as Michele Romano
CVE-2020-2099 BR2020-0000-015468 SECURITY-1682 unclaimed
Inbound TCP Agent Protocol/3 authentication bypass
Credited as Thijs Alkemade from Computest