Jenkins
Jenkins Security Advisory 2020-07-15
2020-07-15 Jul 15, 2020 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-07-15/. 9 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2020-07-15/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
8 lines
Showing 1–8 of 8
CVE-2020-2223
BR2020-0000-014655
SECURITY-1945
unclaimed
Stored XSS vulnerability in console links
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2020-2220
BR2020-0000-014656
SECURITY-1868
unclaimed
Stored XSS vulnerability in job build time trend
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2221
BR2020-0000-014657
SECURITY-1901
unclaimed
Stored XSS vulnerability in upstream cause
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2222
BR2020-0000-014658
SECURITY-1902
unclaimed
Stored XSS vulnerability in 'keep forever' badge icons
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2226
BR2020-0000-014659
SECURITY-1909
unclaimed
Stored XSS vulnerability in Matrix Authorization Strategy Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2227
BR2020-0000-014660
SECURITY-1915
unclaimed
Stored XSS vulnerability in Deployer Framework Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2224
BR2020-0000-014661
SECURITY-1924
unclaimed
Stored XSS vulnerability in single axis builds tooltips in Matrix Project Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2225
BR2020-0000-014662
SECURITY-1925
unclaimed
Stored XSS vulnerability in multiple axis builds tooltips in Matrix Project Plugin
Credited as Wadeck Follonier, CloudBees, Inc.