Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2022-01-12

2022-01-12 Jan 12, 2022 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2022-01-12/. 20 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2022-01-12/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

21 lines
Showing 1–20 of 20 matching · clear filters
CVE-2022-20618 BR2022-0000-011879 SECURITY-2033 unclaimed
Missing permission checks in Bitbucket Branch Source Plugin allow enumerating credentials IDs
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-23118 BR2022-0000-011881 SECURITY-2546 unclaimed
Agent-to-controller security bypass in Debian Package Builder Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-20619 BR2022-0000-011882 SECURITY-2467 unclaimed
CSRF vulnerability in Bitbucket Branch Source Plugin allows capturing credentials
Credited as Devin Nusbaum, CloudBees, Inc.
CVE-2022-23106 BR2022-0000-011883 SECURITY-2141 unclaimed
Non-constant time token comparison in Configuration as Code Plugin
Credited as James Nord, CloudBees, Inc.
CVE-2022-23109 BR2022-0000-011884 SECURITY-2213 unclaimed
Improper credentials masking in HashiCorp Vault Plugin
Credited as Jasen Minton
CVE-2022-23110 BR2022-0000-011885 SECURITY-2287 unclaimed
Stored XSS vulnerability in Publish Over SSH Plugin
Credited as Kevin Guerroudj
CVE-2022-23108 BR2022-0000-011886 SECURITY-2547 unclaimed
Stored XSS vulnerability in Badge Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-20612 BR2022-0000-011887 SECURITY-2558 unclaimed
CSRF vulnerability in build triggers
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-20612 BR2022-0000-011888 SECURITY-2558 unclaimed
CSRF vulnerability in build triggers
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-23113 BR2022-0000-011889 SECURITY-2307 unclaimed
Path traversal vulnerability in Publish Over SSH Plugin
Credited as Kevin Guerroudj, Justin Philip
CVE-2022-23113 BR2022-0000-011890 SECURITY-2307 unclaimed
Path traversal vulnerability in Publish Over SSH Plugin
Credited as Marc Heyries
CVE-2022-23111 BR2022-0000-011891 SECURITY-2290 unclaimed
CSRF vulnerability and missing permission checks in Publish Over SSH Plugin
Credited as Marc Heyries, Justin Philip
CVE-2022-23111 BR2022-0000-011892 SECURITY-2290 unclaimed
CSRF vulnerability and missing permission checks in Publish Over SSH Plugin
Credited as Kevin Guerroudj
CVE-2022-23114 BR2022-0000-011893 SECURITY-2291 unclaimed
Password stored in plain text by Publish Over SSH Plugin
Credited as Marc Heyries, Justin Philip
CVE-2022-23114 BR2022-0000-011894 SECURITY-2291 unclaimed
Password stored in plain text by Publish Over SSH Plugin
Credited as Kevin Guerroudj
CVE-2022-20613 BR2022-0000-011895 SECURITY-2163 unclaimed
CSRF vulnerability and missing permission checks in Mailer Plugin
Credited as Matt Sicker, CloudBees, Inc.
CVE-2022-23115 BR2022-0000-011896 SECURITY-1025 unclaimed
CSRF vulnerability in batch task Plugin
Credited as Oleg Nenashev
CVE-2022-20617 BR2022-0000-011897 SECURITY-1878 unclaimed
OS command execution vulnerability in Docker Commons Plugin
Credited as Tomasz Szuba
CVE-2022-20615 BR2022-0000-011898 SECURITY-2017 unclaimed
Stored XSS vulnerability in Matrix Project Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-23107 BR2022-0000-011899 SECURITY-2090 unclaimed
Path traversal vulnerability in Warnings Plugin
Credited as Wadeck Follonier, CloudBees, Inc.