Jenkins
Jenkins Security Advisory 2023-04-12
2023-04-12 Apr 12, 2023 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2023-04-12/. 14 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2023-04-12/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
16 lines
Showing 1–16 of 16 matching · clear filters
CVE-2023-30530
BR2023-0000-009974
SECURITY-2944
unclaimed
Token stored and displayed in plain text by Consul KV Builder Plugin
Credited as CC Bomber, Kitri BoB
CVE-2023-30523
BR2023-0000-009975
SECURITY-2945
unclaimed
Tokens stored and displayed in plain text by Report Portal Plugin
Credited as CC Bomber, Kitri BoB
CVE-2023-30518
BR2023-0000-009976
SECURITY-2837
unclaimed
Missing permission check in Delinea Secret Server_Platform Plugin allows enumerating credentials IDs
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-30516
BR2023-0000-009977
SECURITY-2840
unclaimed
Disabled SSL/TLS certificate validation for existing configurations in Image Tag Parameter Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-30529
BR2023-0000-009978
SECURITY-3013
unclaimed
CSRF vulnerability in Lucene-Search Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-30519
BR2023-0000-009979
SECURITY-2849
unclaimed
Lack of authentication mechanism in Quay.io trigger Plugin webhook
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30520
BR2023-0000-009980
SECURITY-2850
unclaimed
Stored XSS vulnerability in Quay.io trigger Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30532
BR2023-0000-009981
SECURITY-2851
unclaimed
Lack of authentication mechanism in TurboScript Plugin webhook
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30527
BR2023-0000-009982
SECURITY-2992
unclaimed
Client secret stored and displayed in plain text by wso2id-oauth Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30522
BR2023-0000-009983
SECURITY-2873
unclaimed
Lack of authentication mechanism in Fogbugz Plugin webhook
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-30522
BR2023-0000-009984
SECURITY-2873
unclaimed
Lack of authentication mechanism in Fogbugz Plugin webhook
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-30517
BR2023-0000-009985
SECURITY-2841
unclaimed
SSL/TLS certificate validation unconditionally disabled by NeuVector Vulnerability Scanner Plugin
Credited as Pavel Nakonechnyi, Netcetera AG
CVE-2023-30513
BR2023-0000-009986
SECURITY-3075
unclaimed
Improper masking of credentials in multiple plugins
Credited as Tim Jacomb
CVE-2023-30525
BR2023-0000-009987
SECURITY-2950
unclaimed
CSRF vulnerability and missing permission check in Report Portal Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-30521
BR2023-0000-009988
SECURITY-2872
unclaimed
Lack of authentication mechanism in Assembla merge request builder Plugin webhook
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-30521
BR2023-0000-009989
SECURITY-2872
unclaimed
Lack of authentication mechanism in Assembla merge request builder Plugin webhook
Credited as Kevin Guerroudj, CloudBees, Inc.