Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2020-05-06

2020-05-06 May 6, 2020 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-05-06/. 9 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2020-05-06/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

6 lines
Showing 1–6 of 6
CVE-2020-2185 BR2020-0000-015285 SECURITY-381 unclaimed
Missing SSH host key validation in Amazon EC2 Plugin
Credited as Jesse Glick, CloudBees, Inc.
CVE-2020-2183 BR2020-0000-015286 SECURITY-988 unclaimed
Improper permission checks in Copy Artifact Plugin
Credited as Jesse Glick, CloudBees, Inc.
CVE-2020-2184 BR2020-0000-015287 SECURITY-1094 unclaimed
CSRF vulnerability in CVS Plugin
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2020-2186 BR2020-0000-015288 SECURITY-1408 unclaimed
CSRF vulnerability in Amazon EC2 Plugin
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2020-2187 BR2020-0000-015289 SECURITY-1528 unclaimed
Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
Credited as Raihaan Shouhell, Autodesk, Inc
CVE-2020-2188 BR2020-0000-015290 SECURITY-1844 unclaimed
Users with Overall/Read access can enumerate credentials IDs in Amazon EC2 Plugin
Credited as Wadeck Follonier, CloudBees, Inc.