Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2022-05-17

2022-05-17 May 17, 2022 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2022-05-17/. 14 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2022-05-17/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

13 lines
Showing 1–13 of 13 matching · clear filters
CVE-2022-30971 BR2022-0000-011724 SECURITY-1969 unclaimed
XXE vulnerability in Storable Configs Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-30947 BR2022-0000-011725 SECURITY-2478 unclaimed
Multiple SCM plugins can check out from the controller file system
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-30945 BR2022-0000-011726 SECURITY-359 unclaimed
Sandbox bypass vulnerability through implicitly allowlisted platform Groovy files in Pipeline: Groovy Plugin
Credited as Jesse Glick, CloudBees, Inc.
CVE-2022-30950 BR2022-0000-011727 SECURITY-2604 unclaimed
Multiple vulnerabilities in Windows Remote Command library in windows-slaves Plugin
Credited as Kalle Niemitalo, Procomp Solutions Oy
CVE-2022-30970 BR2022-0000-011728 SECURITY-2267 unclaimed
Stored XSS vulnerability in Autocomplete Parameter Plugin
Credited as Kevin Guerroudj
CVE-2022-30956 BR2022-0000-011729 SECURITY-2600 unclaimed
Stored XSS vulnerability in Rundeck Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-30955 BR2022-0000-011730 SECURITY-2753 unclaimed
Missing permission check in GitLab Plugin allows enumerating credentials IDs
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-30960 BR2022-0000-011731 SECURITY-2717 unclaimed
Stored XSS vulnerabilities in multiple plugins providing additional parameter types
Credited as Kevin Guerroudj, CloudBees, Inc., Wadeck Follonier, CloudBees, Inc.
CVE-2022-30960 BR2022-0000-011732 SECURITY-2717 unclaimed
Stored XSS vulnerabilities in multiple plugins providing additional parameter types
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-30969 BR2022-0000-011733 SECURITY-2322 unclaimed
CSRF vulnerability in Autocomplete Parameter Plugin results in RCE
Credited as Kevin Guerroudj, Justin Philip, Marc Heyries, Wadeck Follonier, CloudBees, Inc.
CVE-2022-30958 BR2022-0000-011734 SECURITY-2093 unclaimed
CSRF vulnerability and missing permission checks in SSH Plugin allow capturing credentials
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-30953 BR2022-0000-011735 SECURITY-2502 unclaimed
CSRF vulnerability and missing permission checks in Blue Ocean Plugin
Credited as Tanner Emek from Tinder Security Labs
CVE-2022-30957 BR2022-0000-011736 SECURITY-2315 unclaimed
Missing permission check in SSH Plugin allows enumerating credentials IDs
Credited as Wadeck Follonier, CloudBees, Inc.