Jenkins
Jenkins Security Advisory 2020-01-29
2020-01-29 Jan 29, 2020 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-01-29/. 10 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2020-01-29/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
11 lines
Showing 1–11 of 11
CVE-2020-2100
BR2020-0000-015458
SECURITY-1641
unclaimed
Jenkins vulnerable to UDP amplification reflection attack
Credited as Adam Thorn, University of Cambridge
CVE-2020-2108
BR2020-0000-015459
SECURITY-1719
unclaimed
XXE vulnerability in WebSphere Deployer Plugin
Credited as Cheng Gao, Alibaba Cloud Intelligence Security Team, https://www.aliyun.com/
CVE-2020-2104
BR2020-0000-015460
SECURITY-1650
unclaimed
Memory usage graphs accessible to anyone with Overall/Read
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2102
BR2020-0000-015461
SECURITY-1660
unclaimed
Non-constant time HMAC comparison
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2103
BR2020-0000-015462
SECURITY-1695
unclaimed
Diagnostic page exposed session cookies
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2103
BR2020-0000-015463
SECURITY-1695
unclaimed
Diagnostic page exposed session cookies
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2106
BR2020-0000-015464
SECURITY-1680
unclaimed
Stored XSS vulnerability in Code Coverage Plugin
Credited as Federico Pellegrin
CVE-2020-2107
BR2020-0000-015465
SECURITY-1565
unclaimed
Fortify Plugin stored credentials in plain text
Credited as James Holderness, IB Boost
CVE-2020-2101
BR2020-0000-015466
SECURITY-1659
unclaimed
Non-constant time comparison of inbound TCP agent connection secret
Credited as Jesse Glick, CloudBees, Inc.
CVE-2020-2105
BR2020-0000-015467
SECURITY-1704
unclaimed
Jenkins REST APIs vulnerable to clickjacking
Credited as Michele Romano
CVE-2020-2099
BR2020-0000-015468
SECURITY-1682
unclaimed
Inbound TCP Agent Protocol/3 authentication bypass
Credited as Thijs Alkemade from Computest