Jenkins
Jenkins Security Advisory 2020-11-04
2020-11-04 Nov 4, 2020 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2020-11-04/. 21 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2020-11-04/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
14 lines
Showing 1–14 of 14
CVE-2020-2312
BR2020-0000-014426
SECURITY-2129
unclaimed
Password written to the build log by SQLPlus Script Runner Plugin
Credited as Chris Maggiulli, Build
CVE-2020-2312
BR2020-0000-014427
SECURITY-2129
unclaimed
Password written to the build log by SQLPlus Script Runner Plugin
Credited as Integrations Engineer, Excelsior College
CVE-2020-2299
BR2020-0000-014428
SECURITY-2117
unclaimed
Login allowed with hardcoded password by Active Directory Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2304
BR2020-0000-014429
SECURITY-2145
unclaimed
XXE vulnerability in Subversion Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2020-2315
BR2020-0000-014430
SECURITY-1900
unclaimed
XXE vulnerability in Visualworks Store Plugin
Credited as Jeff Thompson, CloudBees, Inc.
CVE-2020-2314
BR2020-0000-014431
SECURITY-2058
unclaimed
Password stored in plain text by AppSpider Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2020-2319
BR2020-0000-014432
SECURITY-2084
unclaimed
Password stored in plain text by VMware Lab Manager Slaves Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2020-2318
BR2020-0000-014433
SECURITY-2085
unclaimed
Passwords stored in plain text by Mail Commander Plugin for Jenkins-ci Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2020-2302
BR2020-0000-014434
SECURITY-1999
unclaimed
Missing permission check in Active Directory Plugin allows accessing domain health check page
Credited as Matt Sicker, CloudBees, Inc.
CVE-2020-2300
BR2020-0000-014435
SECURITY-2099
unclaimed
Login allowed with empty password by Active Directory Plugin
Credited as Vic Chappill, Lee Jones
CVE-2020-2300
BR2020-0000-014436
SECURITY-2099
unclaimed
Login allowed with empty password by Active Directory Plugin
Credited as Matthew Maylin, Siemens
CVE-2020-2316
BR2020-0000-014437
SECURITY-1907
unclaimed
Stored XSS vulnerability in Static Analysis Utilities Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2317
BR2020-0000-014438
SECURITY-1918
unclaimed
Stored XSS vulnerability in FindBugs Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2020-2310
BR2020-0000-014439
SECURITY-1943
unclaimed
Missing permission checks in Ansible Plugin allow enumerating credentials IDs
Credited as Wadeck Follonier, CloudBees, Inc.