Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2021-11-12

2021-11-12 Nov 12, 2021 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2021-11-12/. 6 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2021-11-12/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

6 lines
Showing 1–6 of 6
CVE-2021-21701 BR2021-0000-011900 SECURITY-2394 unclaimed
XXE vulnerability in Performance Plugin
Credited as Adith Sudhakar working with Trend Micro Zero Day Initiative
CVE-2021-43576 BR2021-0000-011901 SECURITY-2415 unclaimed
XXE vulnerability in pom2config Plugin
Credited as Adith Sudhakar working with Trend Micro Zero Day Initiative
CVE-2021-43578 BR2021-0000-011902 SECURITY-2525 unclaimed
Agent-to-controller security bypass in Squash TM Publisher (Squash4Jenkins) Plugin allows writing arbitrary files
Credited as Daniel Beck, CloudBees, Inc.
CVE-2021-21700 BR2021-0000-011903 SECURITY-2406 unclaimed
Stored XSS vulnerability in Scriptler Plugin
Credited as Guy Lederfein of Trend Micro
CVE-2021-21699 BR2021-0000-011904 SECURITY-2219 unclaimed
Stored XSS vulnerability in Active Choices Plugin
Credited as Kevin Guerroudj, and, independently, Audrey Prieur of Trend Micro
CVE-2021-43577 BR2021-0000-011905 SECURITY-2488 unclaimed
XXE vulnerability in OWASP Dependency-Check Plugin
Credited as haby0 (Duxiaoman Financial Security Team)