Jenkins
Jenkins Security Advisory 2020-02-12
2020-02-12 Feb 12, 2020 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-02-12/. 20 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2020-02-12/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
21 lines
Showing 1–20 of 20 matching · clear filters
CVE-2020-2122
BR2020-0000-015437
SECURITY-1644
unclaimed
Stored XSS vulnerability in brakeman Plugin
Credited as Adith Sudhakar
CVE-2020-2121
BR2020-0000-015438
SECURITY-1731
unclaimed
RCE vulnerability in Google Kubernetes Engine Plugin
Credited as Daniel Kalinowski of ISEC.pl Research Team
CVE-2020-2123
BR2020-0000-015439
SECURITY-1733
unclaimed
RCE vulnerability in RadarGun Plugin
Credited as Daniel Kalinowski of ISEC.pl Research Team
CVE-2020-2120
BR2020-0000-015440
SECURITY-1751
unclaimed
XXE vulnerability in FitNesse Plugin
Credited as Federico Pellegrin
CVE-2020-2115
BR2020-0000-015441
SECURITY-1752
unclaimed
XXE vulnerability in NUnit Plugin
Credited as Federico Pellegrin
CVE-2020-2133
BR2020-0000-015442
SECURITY-1540
unclaimed
Password stored in plain text by Applatix Plugin
Credited as James Holderness, IB Boost
CVE-2020-2127
BR2020-0000-015443
SECURITY-1547
unclaimed
Credential stored in plain text by BMC Release Package and Deployment Plugin
Credited as James Holderness, IB Boost
CVE-2020-2128
BR2020-0000-015444
SECURITY-1549
unclaimed
Password stored in plain text by ECX Copy Data Management Plugin
Credited as James Holderness, IB Boost
CVE-2020-2129
BR2020-0000-015445
SECURITY-1552
unclaimed
Password stored in plain text by Eagle Tester Plugin
Credited as James Holderness, IB Boost
CVE-2020-2130
BR2020-0000-015446
SECURITY-1553
unclaimed
Passwords stored in plain text by Harvest SCM Plugin
Credited as James Holderness, IB Boost
CVE-2020-2125
BR2020-0000-015447
SECURITY-1558
unclaimed
Credentials stored in plain text by debian-package-builder Plugin
Credited as James Holderness, IB Boost
CVE-2020-2126
BR2020-0000-015448
SECURITY-1559
unclaimed
Token stored in plain text by DigitalOcean Plugin
Credited as James Holderness, IB Boost
CVE-2020-2124
BR2020-0000-015449
SECURITY-1560
unclaimed
Password stored in plain text by Dynamic Extended Choice Parameter Plugin
Credited as James Holderness, IB Boost
CVE-2020-2132
BR2020-0000-015450
SECURITY-1562
unclaimed
Password stored in plain text by Parasoft Environment Manager Plugin
Credited as James Holderness, IB Boost
CVE-2020-2119
BR2020-0000-015451
SECURITY-1717
unclaimed
Client secret transmitted in plain text by Microsoft Entra ID (previously Azure AD) Plugin
Credited as Joseph Petersen @jetersen
CVE-2020-2109
BR2020-0000-015452
SECURITY-1710
unclaimed
Sandbox bypass via default method parameter expression in Pipeline: Groovy Plugin
Credited as Nils Emmerich of ERNW Research GmbH
CVE-2020-2110
BR2020-0000-015453
SECURITY-1713
unclaimed
Sandbox bypass vulnerability in Script Security Plugin
Credited as Nils Emmerich of ERNW Research GmbH
CVE-2020-2112
BR2020-0000-015454
SECURITY-1709
unclaimed
Multiple stored XSS vulnerabilities in Git Parameter Plugin
Credited as Sven Grossmann (@svennergr)
CVE-2020-2114
BR2020-0000-015456
SECURITY-1684
unclaimed
Credential transmitted in plain text by S3 publisher Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2111
BR2020-0000-015457
SECURITY-1725
unclaimed
Stored XSS vulnerability in Subversion Plugin
Credited as Wadeck Follonier, CloudBees, Inc.