Jenkins
Jenkins Security Advisory 2020-07-02
2020-07-02 Jul 2, 2020 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-07-02/. 15 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2020-07-02/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
13 lines
Showing 1–13 of 13
CVE-2020-2209
BR2020-0000-014663
SECURITY-1686
unclaimed
Password stored in plain text by TestComplete support Plugin
Credited as Adam Shaver, BAE Systems
CVE-2020-2202
BR2020-0000-014664
SECURITY-1690
unclaimed
Users with Overall/Read access could enumerate credentials IDs in Fortify on Demand Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2203
BR2020-0000-014665
SECURITY-1691
unclaimed
CSRF vulnerability and missing permission checks in Fortify on Demand Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2215
BR2020-0000-014666
SECURITY-1762
unclaimed
CSRF vulnerability and missing permission checks in Zephyr for JIRA Test Management Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2219
BR2020-0000-014667
SECURITY-1803
unclaimed
Stored XSS vulnerability in Link Column Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2214
BR2020-0000-014668
SECURITY-1811
unclaimed
Content-Security-Policy protection for user content disabled by ZAP Pipeline Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2218
BR2020-0000-014669
SECURITY-1576
unclaimed
Password stored in plain text by HP ALM Quality Center Plugin
Credited as James Holderness, IB Boost
CVE-2020-2210
BR2020-0000-014670
SECURITY-1656
unclaimed
Passwords transmitted in plain text by Stash Branch Parameter Plugin
Credited as Pavel Roskin
Acknowledgement
BR2020-0000-014671
SECURITY-1728
unclaimed
SECURITY-1728
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2217
BR2020-0000-014672
SECURITY-1771
unclaimed
Reflected XSS in Compatibility Action Storage Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2201
BR2020-0000-014673
SECURITY-1775
unclaimed
Stored XSS vulnerability in Sonargraph Integration Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2207
BR2020-0000-014674
SECURITY-1776
unclaimed
Reflected XSS vulnerability in VncViewer Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
Acknowledgement
BR2020-0000-014675
SECURITY-1728
unclaimed
SECURITY-1728
Credited as Daniel Beck, CloudBees, Inc.