Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2020-11-04

2020-11-04 Nov 4, 2020 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-11-04/. 21 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2020-11-04/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

14 lines
Showing 1–14 of 14
CVE-2020-2312 BR2020-0000-014426 SECURITY-2129 unclaimed
Password written to the build log by SQLPlus Script Runner Plugin
Credited as Chris Maggiulli, Build
CVE-2020-2312 BR2020-0000-014427 SECURITY-2129 unclaimed
Password written to the build log by SQLPlus Script Runner Plugin
Credited as Integrations Engineer, Excelsior College
CVE-2020-2299 BR2020-0000-014428 SECURITY-2117 unclaimed
Login allowed with hardcoded password by Active Directory Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2304 BR2020-0000-014429 SECURITY-2145 unclaimed
XXE vulnerability in Subversion Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2315 BR2020-0000-014430 SECURITY-1900 unclaimed
XXE vulnerability in Visualworks Store Plugin
Credited as Jeff Thompson, CloudBees, Inc.
CVE-2020-2314 BR2020-0000-014431 SECURITY-2058 unclaimed
Password stored in plain text by AppSpider Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2020-2319 BR2020-0000-014432 SECURITY-2084 unclaimed
Password stored in plain text by VMware Lab Manager Slaves Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2020-2318 BR2020-0000-014433 SECURITY-2085 unclaimed
Passwords stored in plain text by Mail Commander Plugin for Jenkins-ci Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2020-2302 BR2020-0000-014434 SECURITY-1999 unclaimed
Missing permission check in Active Directory Plugin allows accessing domain health check page
Credited as Matt Sicker, CloudBees, Inc.
CVE-2020-2300 BR2020-0000-014435 SECURITY-2099 unclaimed
Login allowed with empty password by Active Directory Plugin
Credited as Vic Chappill, Lee Jones
CVE-2020-2300 BR2020-0000-014436 SECURITY-2099 unclaimed
Login allowed with empty password by Active Directory Plugin
Credited as Matthew Maylin, Siemens
CVE-2020-2316 BR2020-0000-014437 SECURITY-1907 unclaimed
Stored XSS vulnerability in Static Analysis Utilities Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2317 BR2020-0000-014438 SECURITY-1918 unclaimed
Stored XSS vulnerability in FindBugs Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2310 BR2020-0000-014439 SECURITY-1943 unclaimed
Missing permission checks in Ansible Plugin allow enumerating credentials IDs
Credited as Wadeck Follonier, CloudBees, Inc.