Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2022-11-15

2022-11-15 Nov 15, 2022 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2022-11-15/. 21 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2022-11-15/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

21 lines
Showing 1–21 of 21 matching · clear filters
CVE-2022-45383 BR2022-0000-010097 SECURITY-2804 unclaimed
Incorrect permission checks in Support Core Plugin
Credited as Adrien Lecharpentier, CloudBees, Inc.
CVE-2022-45393 BR2022-0000-010098 SECURITY-2920 unclaimed
CSRF vulnerability and missing permission check in Delete log Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45395 BR2022-0000-010099 SECURITY-2921 unclaimed
XXE vulnerability on agents in CCCC Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45396 BR2022-0000-010100 SECURITY-2927 unclaimed
XXE vulnerability on agents in SourceMonitor Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45397 BR2022-0000-010101 SECURITY-2937 unclaimed
XXE vulnerability on agents in OSF Builder Suite : : XML Linter Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45398 BR2022-0000-010102 SECURITY-2938 unclaimed
CSRF vulnerability and missing permission check in Cluster Statistics Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45400 BR2022-0000-010103 SECURITY-2941 unclaimed
XXE vulnerability in JAPEX Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45382 BR2022-0000-010104 SECURITY-2946 unclaimed
Stored XSS vulnerability in Naginator Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45401 BR2022-0000-010105 SECURITY-2947 unclaimed
Stored XSS vulnerability in Associated Files Plugin
Credited as CC Bomber, Kitri BoB
CVE-2022-45386 BR2022-0000-010106 SECURITY-766 unclaimed
XXE vulnerability on agents in Violations Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-45379 BR2022-0000-010107 SECURITY-2564 unclaimed
Whole-script approval in Script Security Plugin vulnerable to SHA-1 collisions
Credited as Daniel Beck, CloudBees, Inc.
Acknowledgement BR2022-0000-010108 SECURITY-2910 unclaimed
SECURITY-2910
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-45392 BR2022-0000-010109 SECURITY-2912 unclaimed
Passwords stored in plain text by NS-ND Integration Performance Publisher Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2022-45381 BR2022-0000-010110 SECURITY-2949 unclaimed
Arbitrary file read vulnerability in Pipeline Utility Steps Plugin
Credited as James Nord, CloudBees, Inc.
CVE-2022-45384 BR2022-0000-010111 SECURITY-2094 unclaimed
Password stored in plain text by Reverse Proxy Auth Plugin
Credited as Jesse Glick, CloudBees, Inc.
CVE-2022-45388 BR2022-0000-010112 SECURITY-2842 unclaimed
Arbitrary file read vulnerability in Config Rotator Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-45385 BR2022-0000-010113 SECURITY-2843 unclaimed
Lack of authentication mechanism for webhook in CloudBees Docker Hub/Registry Notification Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-45389 BR2022-0000-010114 SECURITY-2853 unclaimed
Lack of authentication mechanism for webhook in XP-Dev Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2022-45387 BR2022-0000-010115 SECURITY-2802 unclaimed
Stored XSS vulnerability in BART Plugin
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-45390 BR2022-0000-010116 SECURITY-2857 unclaimed
Missing permission check in loader.io Plugin allows enumerating credentials IDs
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2022-45380 BR2022-0000-010117 SECURITY-2888 unclaimed
Stored XSS vulnerability in JUnit Plugin
Credited as Wadeck Follonier, CloudBees, Inc.