Jenkins
Jenkins Security Advisory 2023-08-16
2023-08-16 Aug 16, 2023 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2023-08-16/. 15 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2023-08-16/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
18 lines
Showing 1–18 of 18
CVE-2023-40341
BR2023-0000-009788
SECURITY-3116
unclaimed
CSRF vulnerability in Blue Ocean Plugin allows capturing credentials
Credited as Alvaro Muñoz (@pwntester), GitHub Security Lab
CVE-2023-40347
BR2023-0000-009789
SECURITY-3153
unclaimed
Exposure of system-scoped credentials in Maven Artifact ChoiceListProvider (Nexus) Plugin
Credited as Alvaro Muñoz (@pwntester), GitHub Security Lab
CVE-2023-40351
BR2023-0000-009790
SECURITY-3201
unclaimed
CSRF vulnerability in Favorite View Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-40342
BR2023-0000-009791
SECURITY-3223
unclaimed
Stored XSS vulnerability in Flaky Test Handler Plugin
Credited as Andrea Chiera, CloudBees, Inc.
Acknowledgement
BR2023-0000-009792
SECURITY-3214
unclaimed
SECURITY-3214
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-40339
BR2023-0000-009793
SECURITY-3090
unclaimed
Improper masking of credentials in Config File Provider Plugin
Credited as James Nord, CloudBees, Inc.
CVE-2023-40340
BR2023-0000-009794
SECURITY-3196
unclaimed
Improper masking of credentials in NodeJS Plugin
Credited as James Nord, CloudBees, Inc.
CVE-2023-40346
BR2023-0000-009795
SECURITY-3071
unclaimed
Stored XSS vulnerability in Shortcut Job Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-40337
BR2023-0000-009796
SECURITY-3105
unclaimed
CSRF vulnerability in Folders Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-40336
BR2023-0000-009797
SECURITY-3106
unclaimed
CSRF vulnerability in Folders Plugin may approve unsandboxed scripts
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-40338
BR2023-0000-009798
SECURITY-3109
unclaimed
Information disclosure in Folders Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-4303
BR2023-0000-009799
SECURITY-3140
unclaimed
HTML injection vulnerability in Fortify Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-40350
BR2023-0000-009800
SECURITY-2811
unclaimed
Stored XSS vulnerability in Docker Swarm Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-40350
BR2023-0000-009801
SECURITY-2811
unclaimed
Stored XSS vulnerability in Docker Swarm Plugin
Credited as Valdes Che Zogou, CloudBees, Inc.
CVE-2023-40343
BR2023-0000-009802
SECURITY-3229
unclaimed
Non-constant time token comparison in Tuleap Authentication Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-40343
BR2023-0000-009803
SECURITY-3229
unclaimed
Non-constant time token comparison in Tuleap Authentication Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-4301
BR2023-0000-009804
SECURITY-3115
unclaimed
CSRF vulnerability and missing permission checks in Fortify Plugin allow capturing credentials
Credited as Kevin Guerroudj, CloudBees, Inc. and, independently, Alvaro Muñoz (@pwntester), GitHub Security Lab
CVE-2023-40348
BR2023-0000-009805
SECURITY-2894
unclaimed
Unsafe default behavior and information disclosure in Gogs Plugin webhook
Credited as anhnm99