Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2021-01-13

2021-01-13 Jan 13, 2021 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2021-01-13/. 13 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2021-01-13/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

16 lines
Showing 1–16 of 16 matching · clear filters
CVE-2021-21609 BR2021-0000-014381 SECURITY-2047 unclaimed
Missing permission check for paths with specific prefix
Credited as Daniel Beck, CloudBees, Inc.
CVE-2021-21613 BR2021-0000-014382 SECURITY-2098 unclaimed
XSS vulnerability in TICS Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2021-21610 BR2021-0000-014383 SECURITY-2153 unclaimed
Reflected XSS vulnerability in markup formatter preview
Credited as Daniel Beck, CloudBees, Inc.
CVE-2021-21604 BR2021-0000-014384 SECURITY-1923 unclaimed
Improper handling of REST API XML deserialization errors
Credited as Ismail Aydemir at d0nkeysec.org
CVE-2021-21603 BR2021-0000-014385 SECURITY-1889 unclaimed
XSS vulnerability in notification bar
Credited as Jeff Thompson, CloudBees, Inc., Matt Sicker, CloudBees, Inc.
CVE-2021-21603 BR2021-0000-014386 SECURITY-1889 unclaimed
XSS vulnerability in notification bar
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2021-21611 BR2021-0000-014387 SECURITY-2171 unclaimed
Stored XSS vulnerability on new item page
Credited as Jesse Glick, CloudBees, Inc.
CVE-2021-21611 BR2021-0000-014388 SECURITY-2171 unclaimed
Stored XSS vulnerability on new item page
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2021-21612 BR2021-0000-014389 SECURITY-2057 unclaimed
Credentials stored in plain text by tracetronic ecu.test Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2021-21608 BR2021-0000-014390 SECURITY-2035 unclaimed
Stored XSS vulnerability in button labels
Credited as Matt Sicker, CloudBees, Inc.
CVE-2021-21608 BR2021-0000-014391 SECURITY-2035 unclaimed
Stored XSS vulnerability in button labels
Credited as Jesse Glick, CloudBees, Inc.
CVE-2021-21614 BR2021-0000-014392 SECURITY-2156 unclaimed
Credentials stored in plain text by Bumblebee HP ALM Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2021-21602 BR2021-0000-014393 SECURITY-1452 unclaimed
Arbitrary file read vulnerability in workspace browsers
Credited as Travis Emmert from Apple Information Security
CVE-2021-21605 BR2021-0000-014394 SECURITY-2021 unclaimed
Path traversal vulnerability in agent names
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2021-21606 BR2021-0000-014395 SECURITY-2023 unclaimed
Arbitrary file existence check in file fingerprints
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2021-21607 BR2021-0000-014396 SECURITY-2025 unclaimed
Excessive memory allocation in graph URLs leads to denial of service
Credited as Wadeck Follonier, CloudBees, Inc.