Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2020-07-15

2020-07-15 Jul 15, 2020 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-07-15/. 9 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2020-07-15/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

8 lines
Showing 1–8 of 8
CVE-2020-2223 BR2020-0000-014655 SECURITY-1945 unclaimed
Stored XSS vulnerability in console links
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2020-2220 BR2020-0000-014656 SECURITY-1868 unclaimed
Stored XSS vulnerability in job build time trend
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2221 BR2020-0000-014657 SECURITY-1901 unclaimed
Stored XSS vulnerability in upstream cause
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2222 BR2020-0000-014658 SECURITY-1902 unclaimed
Stored XSS vulnerability in 'keep forever' badge icons
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2226 BR2020-0000-014659 SECURITY-1909 unclaimed
Stored XSS vulnerability in Matrix Authorization Strategy Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2227 BR2020-0000-014660 SECURITY-1915 unclaimed
Stored XSS vulnerability in Deployer Framework Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2224 BR2020-0000-014661 SECURITY-1924 unclaimed
Stored XSS vulnerability in single axis builds tooltips in Matrix Project Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2225 BR2020-0000-014662 SECURITY-1925 unclaimed
Stored XSS vulnerability in multiple axis builds tooltips in Matrix Project Plugin
Credited as Wadeck Follonier, CloudBees, Inc.