Jenkins
Jenkins Security Advisory 2020-10-08
2020-10-08 Oct 8, 2020 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-10-08/. 12 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2020-10-08/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
14 lines
Showing 1–14 of 14
CVE-2020-2288
BR2020-0000-014442
SECURITY-1846
unclaimed
Incorrect default pattern in Audit Trail Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2293
BR2020-0000-014443
SECURITY-2046
unclaimed
Arbitrary file read vulnerability in Persona Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2298
BR2020-0000-014444
SECURITY-2097
unclaimed
XXE vulnerability in Nerrvana Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2287
BR2020-0000-014445
SECURITY-1815
unclaimed
Request logging could be bypassed in Audit Trail Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2287
BR2020-0000-014446
SECURITY-1815
unclaimed
Request logging could be bypassed in Audit Trail Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2296
BR2020-0000-014447
SECURITY-2052
unclaimed
CSRF vulnerability in Shared Objects Plugin
Credited as Jeff Thompson, CloudBees, Inc.
CVE-2020-2297
BR2020-0000-014448
SECURITY-2054
unclaimed
Access token stored in plain text by SMS Notification Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2020-2291
BR2020-0000-014449
SECURITY-2065
unclaimed
Password stored in plain text by couchdb-statistics Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2020-2286
BR2020-0000-014450
SECURITY-1767
unclaimed
Improper authorization due to caching in Role-based Authorization Strategy Plugin
Credited as Raihaan Shouhell, Autodesk, Inc
CVE-2020-2292
BR2020-0000-014451
SECURITY-1928
unclaimed
Stored XSS vulnerability in Release Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2289
BR2020-0000-014452
SECURITY-1954
unclaimed
Stored XSS vulnerability in Active Choices Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2290
BR2020-0000-014453
SECURITY-2008
unclaimed
Stored XSS vulnerability in Active Choices Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2294
BR2020-0000-014454
SECURITY-2049
unclaimed
CSRF vulnerability and missing permission checks in Maven Cascade Release Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2294
BR2020-0000-014455
SECURITY-2049
unclaimed
CSRF vulnerability and missing permission checks in Maven Cascade Release Plugin
Credited as Jeff Thompson, CloudBees, Inc.