Jenkins
Jenkins Security Advisory 2022-06-30
2022-06-30 Jun 30, 2022 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2022-06-30/. 30 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2022-06-30/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
35 lines
Showing 1–35 of 35
CVE-2022-34784
BR2022-0000-010205
SECURITY-1118
unclaimed
Stored XSS vulnerability in build-metrics Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-34817
BR2022-0000-010206
SECURITY-2061
unclaimed
CSRF vulnerability and missing permission checks in Failed Job Deactivator Plugin allow disabling jobs
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-34786
BR2022-0000-010207
SECURITY-2332
unclaimed
Stored XSS vulnerability in Rich Text Publisher Plugin
Credited as Justin Philip, Kevin Guerroudj, Marc Heyries
CVE-2022-34783
BR2022-0000-010208
SECURITY-2220
unclaimed
Stored XSS vulnerability in Plot Plugin
Credited as Kevin Guerroudj
CVE-2022-34785
BR2022-0000-010209
SECURITY-2643
unclaimed
Missing permission checks in build-metrics Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34782
BR2022-0000-010210
SECURITY-2650
unclaimed
Incorrect permission check in requests-plugin Plugin allows viewing pending requests
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34815
BR2022-0000-010211
SECURITY-2657
unclaimed
CSRF vulnerability in Request Rename Or Delete Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34812
BR2022-0000-010212
SECURITY-2658
unclaimed
CSRF vulnerability and missing permission checks in XPath Configuration Viewer Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
Acknowledgement
BR2022-0000-010213
SECURITY-2798
unclaimed
SECURITY-2798
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34795
BR2022-0000-010214
SECURITY-2799
unclaimed
Stored XSS vulnerability in Deployment Dashboard Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34810
BR2022-0000-010215
SECURITY-2806
unclaimed
Missing permission check in RQM Plugin allows enumerating credentials IDs
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34777
BR2022-0000-010216
SECURITY-2316
unclaimed
Stored XSS vulnerability in GitLab Plugin
Credited as Kevin Guerroudj, Marc Heyries, Justin Philip, Wadeck Follonier, CloudBees, Inc.
CVE-2022-34808
BR2022-0000-010217
SECURITY-2055
unclaimed
Token stored in plain text by Cisco Spark Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34800
BR2022-0000-010218
SECURITY-2056
unclaimed
Tokens stored in plain text by Build Notifications Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34799
BR2022-0000-010219
SECURITY-2070
unclaimed
Password stored in plain text by Deployment Dashboard Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34807
BR2022-0000-010220
SECURITY-2073
unclaimed
Password stored in plain text by Elasticsearch Query Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34816
BR2022-0000-010221
SECURITY-2080
unclaimed
Passwords stored in plain text by hpe-network-virtualization Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34806
BR2022-0000-010222
SECURITY-2083
unclaimed
Password stored in plain text by Jigomerge Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34802
BR2022-0000-010223
SECURITY-2088
unclaimed
Secrets stored in plain text by RocketChat Notifier Plugin
Credited as Long Nguyen, Viettel Cyber Security and, independently, Son Nguyen (@s0nnguy3n_)
CVE-2022-34802
BR2022-0000-010224
SECURITY-2088
unclaimed
Secrets stored in plain text by RocketChat Notifier Plugin
Credited as Marc Heyries
CVE-2022-34792
BR2022-0000-010225
SECURITY-2000
unclaimed
CSRF vulnerability and missing permission checks in Recipe Plugin allow XXE
Credited as Matt Sicker, ClouBees, Inc., Daniel Beck, CloudBees, Inc.
CVE-2022-34792
BR2022-0000-010226
SECURITY-2000
unclaimed
CSRF vulnerability and missing permission checks in Recipe Plugin allow XXE
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34814
BR2022-0000-010227
SECURITY-1996
unclaimed
Incorrect permission check in Request Rename Or Delete Plugin
Credited as Matt Sicker, CloudBees, Inc.
CVE-2022-34811
BR2022-0000-010228
SECURITY-2002
unclaimed
Missing permission check in XPath Configuration Viewer Plugin allows accessing XPath Configuration Viewer page
Credited as Matt Sicker, CloudBees, Inc.
CVE-2022-34809
BR2022-0000-010229
SECURITY-2155
unclaimed
Password stored in plain text by RQM Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2022-34805
BR2022-0000-010230
SECURITY-2160
unclaimed
Password stored in plain text by Skype notifier Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2022-34791
BR2022-0000-010231
SECURITY-2165
unclaimed
Stored XSS vulnerability in Validating Email Parameter Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2022-34791
BR2022-0000-010232
SECURITY-2165
unclaimed
Stored XSS vulnerability in Validating Email Parameter Plugin
Credited as Kevin Guerroudj
Acknowledgement
BR2022-0000-010233
SECURITY-2773
unclaimed
SECURITY-2773
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-34778
BR2022-0000-010234
SECURITY-2788
unclaimed
XSS vulnerability in TestNG Results Plugin
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-34787
BR2022-0000-010235
SECURITY-1919
unclaimed
XSS vulnerability in Project Inheritance Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-34788
BR2022-0000-010236
SECURITY-1926
unclaimed
Stored XSS vulnerability in Matrix Reloaded Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-34790
BR2022-0000-010237
SECURITY-1939
unclaimed
Stored XSS vulnerability in eXtreme Feedback Panel Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-34789
BR2022-0000-010238
SECURITY-2016
unclaimed
CSRF vulnerability in Matrix Reloaded Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-34803
BR2022-0000-010239
SECURITY-1877
unclaimed
API Key stored in plain text by OpsGenie Plugin
Credited as github.com/jetersen