Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2020-02-12

2020-02-12 Feb 12, 2020 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-02-12/. 20 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2020-02-12/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

21 lines
Showing 1–21 of 21
CVE-2020-2122 BR2020-0000-015437 SECURITY-1644 unclaimed
Stored XSS vulnerability in brakeman Plugin
Credited as Adith Sudhakar
CVE-2020-2121 BR2020-0000-015438 SECURITY-1731 unclaimed
RCE vulnerability in Google Kubernetes Engine Plugin
Credited as Daniel Kalinowski of ISEC.pl Research Team
CVE-2020-2123 BR2020-0000-015439 SECURITY-1733 unclaimed
RCE vulnerability in RadarGun Plugin
Credited as Daniel Kalinowski of ISEC.pl Research Team
CVE-2020-2120 BR2020-0000-015440 SECURITY-1751 unclaimed
XXE vulnerability in FitNesse Plugin
Credited as Federico Pellegrin
CVE-2020-2115 BR2020-0000-015441 SECURITY-1752 unclaimed
XXE vulnerability in NUnit Plugin
Credited as Federico Pellegrin
CVE-2020-2133 BR2020-0000-015442 SECURITY-1540 unclaimed
Password stored in plain text by Applatix Plugin
Credited as James Holderness, IB Boost
CVE-2020-2127 BR2020-0000-015443 SECURITY-1547 unclaimed
Credential stored in plain text by BMC Release Package and Deployment Plugin
Credited as James Holderness, IB Boost
CVE-2020-2128 BR2020-0000-015444 SECURITY-1549 unclaimed
Password stored in plain text by ECX Copy Data Management Plugin
Credited as James Holderness, IB Boost
CVE-2020-2129 BR2020-0000-015445 SECURITY-1552 unclaimed
Password stored in plain text by Eagle Tester Plugin
Credited as James Holderness, IB Boost
CVE-2020-2130 BR2020-0000-015446 SECURITY-1553 unclaimed
Passwords stored in plain text by Harvest SCM Plugin
Credited as James Holderness, IB Boost
CVE-2020-2125 BR2020-0000-015447 SECURITY-1558 unclaimed
Credentials stored in plain text by debian-package-builder Plugin
Credited as James Holderness, IB Boost
CVE-2020-2126 BR2020-0000-015448 SECURITY-1559 unclaimed
Token stored in plain text by DigitalOcean Plugin
Credited as James Holderness, IB Boost
CVE-2020-2124 BR2020-0000-015449 SECURITY-1560 unclaimed
Password stored in plain text by Dynamic Extended Choice Parameter Plugin
Credited as James Holderness, IB Boost
CVE-2020-2132 BR2020-0000-015450 SECURITY-1562 unclaimed
Password stored in plain text by Parasoft Environment Manager Plugin
Credited as James Holderness, IB Boost
CVE-2020-2119 BR2020-0000-015451 SECURITY-1717 unclaimed
Client secret transmitted in plain text by Microsoft Entra ID (previously Azure AD) Plugin
Credited as Joseph Petersen @jetersen
CVE-2020-2109 BR2020-0000-015452 SECURITY-1710 unclaimed
Sandbox bypass via default method parameter expression in Pipeline: Groovy Plugin
Credited as Nils Emmerich of ERNW Research GmbH
CVE-2020-2110 BR2020-0000-015453 SECURITY-1713 unclaimed
Sandbox bypass vulnerability in Script Security Plugin
Credited as Nils Emmerich of ERNW Research GmbH
CVE-2020-2112 BR2020-0000-015454 SECURITY-1709 unclaimed
Multiple stored XSS vulnerabilities in Git Parameter Plugin
Credited as Sven Grossmann (@svennergr)
Acknowledgement BR2020-0000-015455 SECURITY-812 unclaimed
SECURITY-812
Credited as Thomas de Grenier de Latour
CVE-2020-2114 BR2020-0000-015456 SECURITY-1684 unclaimed
Credential transmitted in plain text by S3 publisher Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2111 BR2020-0000-015457 SECURITY-1725 unclaimed
Stored XSS vulnerability in Subversion Plugin
Credited as Wadeck Follonier, CloudBees, Inc.