Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2023-09-20

2023-09-20 Sep 20, 2023 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2023-09-20/. 7 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2023-09-20/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

7 lines
Showing 1–7 of 7
CVE-2023-43500 BR2023-0000-009717 SECURITY-3226 unclaimed
CSRF vulnerability and missing permission check in Build Failure Analyzer Plugin allow SSRF
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-43502 BR2023-0000-009718 SECURITY-3239 unclaimed
CSRF vulnerability in Build Failure Analyzer Plugin allows deleting Failure Causes
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-43496 BR2023-0000-009719 SECURITY-3072 unclaimed
Temporary plugin file created with insecure permissions
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-43497 BR2023-0000-009720 SECURITY-3073 unclaimed
Temporary uploaded file created with insecure permissions
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-43499 BR2023-0000-009721 SECURITY-3244 unclaimed
Stored XSS vulnerability in Build Failure Analyzer Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-43495 BR2023-0000-009722 SECURITY-3245 unclaimed
Stored XSS vulnerability
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-43494 BR2023-0000-009723 SECURITY-3261 unclaimed
Builds can be filtered by values of sensitive build variables
Credited as sunita