Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2022-07-27

2022-07-27 Jul 27, 2022 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2022-07-27/. 27 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2022-07-27/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

24 lines
Showing 1–24 of 24
CVE-2022-36894 BR2022-0000-010181 SECURITY-2413 unclaimed
Arbitrary file write vulnerability in CLIF Performance Testing Plugin
Credited as Brian Hysell, Synopsys Software Integrity Group
CVE-2022-36882 BR2022-0000-010182 SECURITY-284 unclaimed
Lack of authentication mechanism in Git Plugin webhook
Credited as Daniel Beck, CloudBees, Inc.
Acknowledgement BR2022-0000-010183 SECURITY-1375 unclaimed
SECURITY-1375
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-36891 BR2022-0000-010184 SECURITY-2205 unclaimed
Missing permission check in Deployer Framework Plugin allows reading deployment logs
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-36890 BR2022-0000-010185 SECURITY-2206 unclaimed
Path traversal vulnerability in Deployer Framework Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-36892 BR2022-0000-010186 SECURITY-2402 unclaimed
Missing permission check in rhnpush-plugin Plugin allows listing workspace contents
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-36893 BR2022-0000-010187 SECURITY-2403 unclaimed
Missing permission check in rpmsign-plugin Plugin allows listing workspace contents
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-36915 BR2022-0000-010188 SECURITY-2404 unclaimed
Missing permission check in Android Signing Plugin allows listing workspace contents
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-36889 BR2022-0000-010189 SECURITY-2764 unclaimed
Path traversal vulnerability in Deployer Framework Plugin allows reading arbitrary files
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-36881 BR2022-0000-010190 SECURITY-1468 unclaimed
Missing hostname verification in Git client Plugin
Credited as James Nord, CloudBees, Inc., and, independently, Alex Kurtser, Satori Cyber Ltd.
CVE-2022-36910 BR2022-0000-010191 SECURITY-2048 unclaimed
Missing permission checks in Lucene-Search Plugin
Credited as Jeff Thompson, CloudBees, Inc.
CVE-2022-36885 BR2022-0000-010192 SECURITY-1849 unclaimed
Non-constant time webhook signature comparison in GitHub Plugin
Credited as Jesse Glick, CloudBees, Inc.
CVE-2022-36888 BR2022-0000-010193 SECURITY-2593 unclaimed
Missing permission checks in HashiCorp Vault Plugin allow capturing credentials
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-36916 BR2022-0000-010194 SECURITY-2656 unclaimed
CSRF vulnerability and missing permission check in Google Cloud Backup Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
Acknowledgement BR2022-0000-010195 SECURITY-2665 unclaimed
SECURITY-2665
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-36902 BR2022-0000-010196 SECURITY-2682 unclaimed
Stored XSS vulnerability in Dynamic Extended Choice Parameter Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-36905 BR2022-0000-010197 SECURITY-2686 unclaimed
Stored XSS vulnerability in Maven Metadata Plugin for Jenkins CI server Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-36901 BR2022-0000-010198 SECURITY-2053 unclaimed
Passwords stored in plain text by HTTP Request Plugin
Credited as Long Nguyen, Viettel Cyber Security
CVE-2022-36918 BR2022-0000-010199 SECURITY-2747 unclaimed
Missing permission check in Buckminster Plugin
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-36887 BR2022-0000-010200 SECURITY-2766 unclaimed
CSRF vulnerability in Job Configuration History Plugin
Credited as Valdes Che Zogou, CloudBees, Inc.
Acknowledgement BR2022-0000-010201 SECURITY-2790 unclaimed
SECURITY-2790
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-36922 BR2022-0000-010202 SECURITY-2812 unclaimed
Reflected XSS vulnerability in Lucene-Search Plugin
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-36914 BR2022-0000-010203 SECURITY-2210 unclaimed
Missing permission check in Files Found Trigger Plugin allows listing the Jenkins controller file system
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2022-36886 BR2022-0000-010204 SECURITY-2762 unclaimed
CSRF vulnerability in External Monitor Job Type Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.