Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2020-07-02

2020-07-02 Jul 2, 2020 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-07-02/. 15 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2020-07-02/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

13 lines
Showing 1–13 of 13
CVE-2020-2209 BR2020-0000-014663 SECURITY-1686 unclaimed
Password stored in plain text by TestComplete support Plugin
Credited as Adam Shaver, BAE Systems
CVE-2020-2202 BR2020-0000-014664 SECURITY-1690 unclaimed
Users with Overall/Read access could enumerate credentials IDs in Fortify on Demand Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2203 BR2020-0000-014665 SECURITY-1691 unclaimed
CSRF vulnerability and missing permission checks in Fortify on Demand Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2215 BR2020-0000-014666 SECURITY-1762 unclaimed
CSRF vulnerability and missing permission checks in Zephyr for JIRA Test Management Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2219 BR2020-0000-014667 SECURITY-1803 unclaimed
Stored XSS vulnerability in Link Column Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2214 BR2020-0000-014668 SECURITY-1811 unclaimed
Content-Security-Policy protection for user content disabled by ZAP Pipeline Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2218 BR2020-0000-014669 SECURITY-1576 unclaimed
Password stored in plain text by HP ALM Quality Center Plugin
Credited as James Holderness, IB Boost
CVE-2020-2210 BR2020-0000-014670 SECURITY-1656 unclaimed
Passwords transmitted in plain text by Stash Branch Parameter Plugin
Credited as Pavel Roskin
Acknowledgement BR2020-0000-014671 SECURITY-1728 unclaimed
SECURITY-1728
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2217 BR2020-0000-014672 SECURITY-1771 unclaimed
Reflected XSS in Compatibility Action Storage Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2201 BR2020-0000-014673 SECURITY-1775 unclaimed
Stored XSS vulnerability in Sonargraph Integration Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2207 BR2020-0000-014674 SECURITY-1776 unclaimed
Reflected XSS vulnerability in VncViewer Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
Acknowledgement BR2020-0000-014675 SECURITY-1728 unclaimed
SECURITY-1728
Credited as Daniel Beck, CloudBees, Inc.