Jenkins
Jenkins Security Advisory 2021-01-13
2021-01-13 Jan 13, 2021 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2021-01-13/. 13 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2021-01-13/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
16 lines
Showing 1–16 of 16 matching · clear filters
CVE-2021-21609
BR2021-0000-014381
SECURITY-2047
unclaimed
Missing permission check for paths with specific prefix
Credited as Daniel Beck, CloudBees, Inc.
CVE-2021-21613
BR2021-0000-014382
SECURITY-2098
unclaimed
XSS vulnerability in TICS Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2021-21610
BR2021-0000-014383
SECURITY-2153
unclaimed
Reflected XSS vulnerability in markup formatter preview
Credited as Daniel Beck, CloudBees, Inc.
CVE-2021-21604
BR2021-0000-014384
SECURITY-1923
unclaimed
Improper handling of REST API XML deserialization errors
Credited as Ismail Aydemir at d0nkeysec.org
CVE-2021-21603
BR2021-0000-014385
SECURITY-1889
unclaimed
XSS vulnerability in notification bar
Credited as Jeff Thompson, CloudBees, Inc., Matt Sicker, CloudBees, Inc.
CVE-2021-21603
BR2021-0000-014386
SECURITY-1889
unclaimed
XSS vulnerability in notification bar
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2021-21611
BR2021-0000-014387
SECURITY-2171
unclaimed
Stored XSS vulnerability on new item page
Credited as Jesse Glick, CloudBees, Inc.
CVE-2021-21611
BR2021-0000-014388
SECURITY-2171
unclaimed
Stored XSS vulnerability on new item page
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2021-21612
BR2021-0000-014389
SECURITY-2057
unclaimed
Credentials stored in plain text by tracetronic ecu.test Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2021-21608
BR2021-0000-014390
SECURITY-2035
unclaimed
Stored XSS vulnerability in button labels
Credited as Matt Sicker, CloudBees, Inc.
CVE-2021-21608
BR2021-0000-014391
SECURITY-2035
unclaimed
Stored XSS vulnerability in button labels
Credited as Jesse Glick, CloudBees, Inc.
CVE-2021-21614
BR2021-0000-014392
SECURITY-2156
unclaimed
Credentials stored in plain text by Bumblebee HP ALM Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2021-21602
BR2021-0000-014393
SECURITY-1452
unclaimed
Arbitrary file read vulnerability in workspace browsers
Credited as Travis Emmert from Apple Information Security
CVE-2021-21605
BR2021-0000-014394
SECURITY-2021
unclaimed
Path traversal vulnerability in agent names
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2021-21606
BR2021-0000-014395
SECURITY-2023
unclaimed
Arbitrary file existence check in file fingerprints
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2021-21607
BR2021-0000-014396
SECURITY-2025
unclaimed
Excessive memory allocation in graph URLs leads to denial of service
Credited as Wadeck Follonier, CloudBees, Inc.