Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2023-04-12

2023-04-12 Apr 12, 2023 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2023-04-12/. 14 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2023-04-12/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

16 lines
Showing 1–16 of 16 matching · clear filters
CVE-2023-30530 BR2023-0000-009974 SECURITY-2944 unclaimed
Token stored and displayed in plain text by Consul KV Builder Plugin
Credited as CC Bomber, Kitri BoB
CVE-2023-30523 BR2023-0000-009975 SECURITY-2945 unclaimed
Tokens stored and displayed in plain text by Report Portal Plugin
Credited as CC Bomber, Kitri BoB
CVE-2023-30518 BR2023-0000-009976 SECURITY-2837 unclaimed
Missing permission check in Delinea Secret Server_Platform Plugin allows enumerating credentials IDs
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-30516 BR2023-0000-009977 SECURITY-2840 unclaimed
Disabled SSL/TLS certificate validation for existing configurations in Image Tag Parameter Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-30529 BR2023-0000-009978 SECURITY-3013 unclaimed
CSRF vulnerability in Lucene-Search Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-30519 BR2023-0000-009979 SECURITY-2849 unclaimed
Lack of authentication mechanism in Quay.io trigger Plugin webhook
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30520 BR2023-0000-009980 SECURITY-2850 unclaimed
Stored XSS vulnerability in Quay.io trigger Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30532 BR2023-0000-009981 SECURITY-2851 unclaimed
Lack of authentication mechanism in TurboScript Plugin webhook
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30527 BR2023-0000-009982 SECURITY-2992 unclaimed
Client secret stored and displayed in plain text by wso2id-oauth Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30522 BR2023-0000-009983 SECURITY-2873 unclaimed
Lack of authentication mechanism in Fogbugz Plugin webhook
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30522 BR2023-0000-009984 SECURITY-2873 unclaimed
Lack of authentication mechanism in Fogbugz Plugin webhook
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-30517 BR2023-0000-009985 SECURITY-2841 unclaimed
SSL/TLS certificate validation unconditionally disabled by NeuVector Vulnerability Scanner Plugin
Credited as Pavel Nakonechnyi, Netcetera AG
CVE-2023-30513 BR2023-0000-009986 SECURITY-3075 unclaimed
Improper masking of credentials in multiple plugins
Credited as Tim Jacomb
CVE-2023-30525 BR2023-0000-009987 SECURITY-2950 unclaimed
CSRF vulnerability and missing permission check in Report Portal Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-30521 BR2023-0000-009988 SECURITY-2872 unclaimed
Lack of authentication mechanism in Assembla merge request builder Plugin webhook
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-30521 BR2023-0000-009989 SECURITY-2872 unclaimed
Lack of authentication mechanism in Assembla merge request builder Plugin webhook
Credited as Kevin Guerroudj, CloudBees, Inc.