Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2020-09-01

2020-09-01 Sep 1, 2020 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-09-01/. 11 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2020-09-01/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

10 lines
Showing 1–10 of 10
CVE-2020-2245 BR2020-0000-014485 SECURITY-1829 unclaimed
XXE vulnerability in Valgrind Plugin
Credited as Federico Pellegrin
CVE-2020-2246 BR2020-0000-014486 SECURITY-1830 unclaimed
Stored XSS vulnerability in Valgrind Plugin
Credited as Federico Pellegrin
CVE-2020-2247 BR2020-0000-014487 SECURITY-1831 unclaimed
XXE vulnerability in Klocwork Analysis Plugin
Credited as Federico Pellegrin
CVE-2020-2249 BR2020-0000-014488 SECURITY-1506 unclaimed
Credentials stored in plain text by tfs Plugin
Credited as James Holderness, IB Boost
CVE-2020-2248 BR2020-0000-014489 SECURITY-1905 unclaimed
Reflected XSS vulnerability in JSGames Plugin
Credited as Jonathan Leitschuh
CVE-2020-2240 BR2020-0000-014490 SECURITY-1023 unclaimed
CSRF vulnerability in Database Plugin
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2020-2241 BR2020-0000-014491 SECURITY-1024 unclaimed
CSRF vulnerability and missing permission checks in Database Plugin
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2020-2244 BR2020-0000-014492 SECURITY-1770 unclaimed
XSS vulnerability in Build Failure Analyzer Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2238 BR2020-0000-014493 SECURITY-1884 unclaimed
Stored XSS vulnerability in Git Parameter Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2243 BR2020-0000-014494 SECURITY-1936 unclaimed
Stored XSS vulnerability in Cadence vManager Plugin
Credited as Wadeck Follonier, CloudBees, Inc.