Jenkins
Jenkins Security Advisory 2021-11-12
2021-11-12 Nov 12, 2021 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2021-11-12/. 6 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2021-11-12/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
6 lines
Showing 1–6 of 6
CVE-2021-21701
BR2021-0000-011900
SECURITY-2394
unclaimed
XXE vulnerability in Performance Plugin
Credited as Adith Sudhakar working with Trend Micro Zero Day Initiative
CVE-2021-43576
BR2021-0000-011901
SECURITY-2415
unclaimed
XXE vulnerability in pom2config Plugin
Credited as Adith Sudhakar working with Trend Micro Zero Day Initiative
CVE-2021-43578
BR2021-0000-011902
SECURITY-2525
unclaimed
Agent-to-controller security bypass in Squash TM Publisher (Squash4Jenkins) Plugin allows writing arbitrary files
Credited as Daniel Beck, CloudBees, Inc.
CVE-2021-21700
BR2021-0000-011903
SECURITY-2406
unclaimed
Stored XSS vulnerability in Scriptler Plugin
Credited as Guy Lederfein of Trend Micro
CVE-2021-21699
BR2021-0000-011904
SECURITY-2219
unclaimed
Stored XSS vulnerability in Active Choices Plugin
Credited as Kevin Guerroudj, and, independently, Audrey Prieur of Trend Micro
CVE-2021-43577
BR2021-0000-011905
SECURITY-2488
unclaimed
XXE vulnerability in OWASP Dependency-Check Plugin
Credited as haby0 (Duxiaoman Financial Security Team)