Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2022-06-30

2022-06-30 Jun 30, 2022 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2022-06-30/. 30 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2022-06-30/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

35 lines
Showing 1–35 of 35
CVE-2022-34784 BR2022-0000-010205 SECURITY-1118 unclaimed
Stored XSS vulnerability in build-metrics Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-34817 BR2022-0000-010206 SECURITY-2061 unclaimed
CSRF vulnerability and missing permission checks in Failed Job Deactivator Plugin allow disabling jobs
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-34786 BR2022-0000-010207 SECURITY-2332 unclaimed
Stored XSS vulnerability in Rich Text Publisher Plugin
Credited as Justin Philip, Kevin Guerroudj, Marc Heyries
CVE-2022-34783 BR2022-0000-010208 SECURITY-2220 unclaimed
Stored XSS vulnerability in Plot Plugin
Credited as Kevin Guerroudj
CVE-2022-34785 BR2022-0000-010209 SECURITY-2643 unclaimed
Missing permission checks in build-metrics Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34782 BR2022-0000-010210 SECURITY-2650 unclaimed
Incorrect permission check in requests-plugin Plugin allows viewing pending requests
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34815 BR2022-0000-010211 SECURITY-2657 unclaimed
CSRF vulnerability in Request Rename Or Delete Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34812 BR2022-0000-010212 SECURITY-2658 unclaimed
CSRF vulnerability and missing permission checks in XPath Configuration Viewer Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
Acknowledgement BR2022-0000-010213 SECURITY-2798 unclaimed
SECURITY-2798
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34795 BR2022-0000-010214 SECURITY-2799 unclaimed
Stored XSS vulnerability in Deployment Dashboard Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34810 BR2022-0000-010215 SECURITY-2806 unclaimed
Missing permission check in RQM Plugin allows enumerating credentials IDs
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34777 BR2022-0000-010216 SECURITY-2316 unclaimed
Stored XSS vulnerability in GitLab Plugin
Credited as Kevin Guerroudj, Marc Heyries, Justin Philip, Wadeck Follonier, CloudBees, Inc.
CVE-2022-34808 BR2022-0000-010217 SECURITY-2055 unclaimed
Token stored in plain text by Cisco Spark Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34800 BR2022-0000-010218 SECURITY-2056 unclaimed
Tokens stored in plain text by Build Notifications Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34799 BR2022-0000-010219 SECURITY-2070 unclaimed
Password stored in plain text by Deployment Dashboard Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34807 BR2022-0000-010220 SECURITY-2073 unclaimed
Password stored in plain text by Elasticsearch Query Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34816 BR2022-0000-010221 SECURITY-2080 unclaimed
Passwords stored in plain text by hpe-network-virtualization Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34806 BR2022-0000-010222 SECURITY-2083 unclaimed
Password stored in plain text by Jigomerge Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-34802 BR2022-0000-010223 SECURITY-2088 unclaimed
Secrets stored in plain text by RocketChat Notifier Plugin
Credited as Long Nguyen, Viettel Cyber Security and, independently, Son Nguyen (@s0nnguy3n_)
CVE-2022-34802 BR2022-0000-010224 SECURITY-2088 unclaimed
Secrets stored in plain text by RocketChat Notifier Plugin
Credited as Marc Heyries
CVE-2022-34792 BR2022-0000-010225 SECURITY-2000 unclaimed
CSRF vulnerability and missing permission checks in Recipe Plugin allow XXE
Credited as Matt Sicker, ClouBees, Inc., Daniel Beck, CloudBees, Inc.
CVE-2022-34792 BR2022-0000-010226 SECURITY-2000 unclaimed
CSRF vulnerability and missing permission checks in Recipe Plugin allow XXE
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-34814 BR2022-0000-010227 SECURITY-1996 unclaimed
Incorrect permission check in Request Rename Or Delete Plugin
Credited as Matt Sicker, CloudBees, Inc.
CVE-2022-34811 BR2022-0000-010228 SECURITY-2002 unclaimed
Missing permission check in XPath Configuration Viewer Plugin allows accessing XPath Configuration Viewer page
Credited as Matt Sicker, CloudBees, Inc.
CVE-2022-34809 BR2022-0000-010229 SECURITY-2155 unclaimed
Password stored in plain text by RQM Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2022-34805 BR2022-0000-010230 SECURITY-2160 unclaimed
Password stored in plain text by Skype notifier Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2022-34791 BR2022-0000-010231 SECURITY-2165 unclaimed
Stored XSS vulnerability in Validating Email Parameter Plugin
Credited as Son Nguyen (@s0nnguy3n_)
CVE-2022-34791 BR2022-0000-010232 SECURITY-2165 unclaimed
Stored XSS vulnerability in Validating Email Parameter Plugin
Credited as Kevin Guerroudj
Acknowledgement BR2022-0000-010233 SECURITY-2773 unclaimed
SECURITY-2773
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-34778 BR2022-0000-010234 SECURITY-2788 unclaimed
XSS vulnerability in TestNG Results Plugin
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-34787 BR2022-0000-010235 SECURITY-1919 unclaimed
XSS vulnerability in Project Inheritance Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-34788 BR2022-0000-010236 SECURITY-1926 unclaimed
Stored XSS vulnerability in Matrix Reloaded Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-34790 BR2022-0000-010237 SECURITY-1939 unclaimed
Stored XSS vulnerability in eXtreme Feedback Panel Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-34789 BR2022-0000-010238 SECURITY-2016 unclaimed
CSRF vulnerability in Matrix Reloaded Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-34803 BR2022-0000-010239 SECURITY-1877 unclaimed
API Key stored in plain text by OpsGenie Plugin
Credited as github.com/jetersen