Jenkins
Jenkins Security Advisory 2022-03-15
2022-03-15 Mar 15, 2022 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2022-03-15/. 20 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2022-03-15/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
21 lines
Showing 1–21 of 21
CVE-2022-27201
BR2022-0000-011775
SECURITY-2124
unclaimed
Agent-to-controller security bypass in Semantic Versioning Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-27210
BR2022-0000-011776
SECURITY-2681
unclaimed
CSRF vulnerability and missing permission checks in kubernetes-cd Plugin allow capturing credentials
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-27195
BR2022-0000-011777
SECURITY-2185
unclaimed
Sensitive parameter values captured in build metadata files by Parameterized Trigger Plugin
Credited as Gunther Rademacher
CVE-2022-27208
BR2022-0000-011778
SECURITY-2096
unclaimed
Arbitrary file read vulnerability in kubernetes-cd Plugin
Credited as Jesse Glick, CloudBees, Inc.
CVE-2022-27213
BR2022-0000-011779
SECURITY-2252
unclaimed
Stored XSS vulnerability in Environment Dashboard Plugin
Credited as Justin Philip
CVE-2022-27202
BR2022-0000-011780
SECURITY-2232
unclaimed
Stored XSS vulnerability in Extended Choice Parameter Plugin
Credited as Kevin Guerroudj
CVE-2022-27217
BR2022-0000-011781
SECURITY-2238
unclaimed
Passwords stored in plain text by Vmware vRealize CodeStream Plugin
Credited as Kevin Guerroudj
CVE-2022-27209
BR2022-0000-011782
SECURITY-2636
unclaimed
Missing permission checks in kubernetes-cd Plugin allow enumerating credentials IDs
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-27200
BR2022-0000-011783
SECURITY-2646
unclaimed
Stored XSS vulnerability in Folder-based Authorization Strategy Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-27196
BR2022-0000-011784
SECURITY-2557
unclaimed
Stored XSS vulnerability in Favorite Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-27196
BR2022-0000-011785
SECURITY-2557
unclaimed
Stored XSS vulnerability in Favorite Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-27206
BR2022-0000-011786
SECURITY-1891
unclaimed
Client Secret stored in plain text by GitLab Authentication Plugin
Credited as Matt Sicker, CloudBees, Inc. and, independently, Marc Heyries
CVE-2022-27204
BR2022-0000-011787
SECURITY-1350
unclaimed
CSRF vulnerability and missing permission checks in Extended Choice Parameter Plugin allow SSRF
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2022-27203
BR2022-0000-011788
SECURITY-1351
unclaimed
Arbitrary JSON and property file read vulnerability in Extended Choice Parameter Plugin
Credited as Oleg Nenashev, CloudBees, Inc.
CVE-2022-27218
BR2022-0000-011789
SECURITY-2273
unclaimed
Personal tokens stored in plain text by incapptic connect uploader Plugin
Credited as Quentin Parra
CVE-2022-27214
BR2022-0000-011790
SECURITY-2274
unclaimed
CSRF vulnerability and missing permission checks in Release Helper Plugin
Credited as Quentin Parra
CVE-2022-27216
BR2022-0000-011791
SECURITY-2159
unclaimed
Passwords stored in plain text by dbCharts Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2022-27212
BR2022-0000-011792
SECURITY-2167
unclaimed
Stored XSS vulnerability in List Git Branches Parameter Plugin
Credited as Son Nguyen (@s0nnguy3n_), and, independently, Kevin Guerroudj
CVE-2022-27197
BR2022-0000-011793
SECURITY-2559
unclaimed
Stored XSS vulnerability in Dashboard View Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-27197
BR2022-0000-011794
SECURITY-2559
unclaimed
Stored XSS vulnerability in Dashboard View Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-27207
BR2022-0000-011795
SECURITY-1886
unclaimed
Stored XSS vulnerability in global-build-stats Plugin
Credited as Wadeck Follonier, CloudBees, Inc., and, independently, Kevin Guerroudj