Jenkins
Jenkins Security Advisory 2022-11-15
2022-11-15 Nov 15, 2022 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2022-11-15/. 21 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2022-11-15/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
21 lines
Showing 1–20 of 20 matching · clear filters
CVE-2022-45383
BR2022-0000-010097
SECURITY-2804
unclaimed
Incorrect permission checks in Support Core Plugin
Credited as Adrien Lecharpentier, CloudBees, Inc.
CVE-2022-45393
BR2022-0000-010098
SECURITY-2920
unclaimed
CSRF vulnerability and missing permission check in Delete log Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45395
BR2022-0000-010099
SECURITY-2921
unclaimed
XXE vulnerability on agents in CCCC Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45396
BR2022-0000-010100
SECURITY-2927
unclaimed
XXE vulnerability on agents in SourceMonitor Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45397
BR2022-0000-010101
SECURITY-2937
unclaimed
XXE vulnerability on agents in OSF Builder Suite : : XML Linter Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45398
BR2022-0000-010102
SECURITY-2938
unclaimed
CSRF vulnerability and missing permission check in Cluster Statistics Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45400
BR2022-0000-010103
SECURITY-2941
unclaimed
XXE vulnerability in JAPEX Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45382
BR2022-0000-010104
SECURITY-2946
unclaimed
Stored XSS vulnerability in Naginator Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45401
BR2022-0000-010105
SECURITY-2947
unclaimed
Stored XSS vulnerability in Associated Files Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45386
BR2022-0000-010106
SECURITY-766
unclaimed
XXE vulnerability on agents in Violations Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-45379
BR2022-0000-010107
SECURITY-2564
unclaimed
Whole-script approval in Script Security Plugin vulnerable to SHA-1 collisions
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-45392
BR2022-0000-010109
SECURITY-2912
unclaimed
Passwords stored in plain text by NS-ND Integration Performance Publisher Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-45381
BR2022-0000-010110
SECURITY-2949
unclaimed
Arbitrary file read vulnerability in Pipeline Utility Steps Plugin
Credited as James Nord, CloudBees, Inc.
CVE-2022-45384
BR2022-0000-010111
SECURITY-2094
unclaimed
Password stored in plain text by Reverse Proxy Auth Plugin
Credited as Jesse Glick, CloudBees, Inc.
CVE-2022-45388
BR2022-0000-010112
SECURITY-2842
unclaimed
Arbitrary file read vulnerability in Config Rotator Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-45385
BR2022-0000-010113
SECURITY-2843
unclaimed
Lack of authentication mechanism for webhook in CloudBees Docker Hub/Registry Notification Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-45389
BR2022-0000-010114
SECURITY-2853
unclaimed
Lack of authentication mechanism for webhook in XP-Dev Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-45387
BR2022-0000-010115
SECURITY-2802
unclaimed
Stored XSS vulnerability in BART Plugin
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-45390
BR2022-0000-010116
SECURITY-2857
unclaimed
Missing permission check in loader.io Plugin allows enumerating credentials IDs
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-45380
BR2022-0000-010117
SECURITY-2888
unclaimed
Stored XSS vulnerability in JUnit Plugin
Credited as Wadeck Follonier, CloudBees, Inc.