Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2023-10-25

2023-10-25 Oct 25, 2023 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2023-10-25/. 11 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2023-10-25/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

11 lines
Showing 1–11 of 11 matching · clear filters
CVE-2023-46653 BR2023-0000-009675 SECURITY-3202 unclaimed
Exposure of token through logs in lambdatest-automation Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-46652 BR2023-0000-009676 SECURITY-3222 unclaimed
Missing permission check in lambdatest-automation Plugin allows enumerating credentials IDs
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-46654 BR2023-0000-009677 SECURITY-3237 unclaimed
Arbitrary file deletion vulnerability in CloudBees CD Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-46655 BR2023-0000-009678 SECURITY-3238 unclaimed
Arbitrary file read vulnerability in CloudBees CD Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-46651 BR2023-0000-009679 SECURITY-3265 unclaimed
Exposure of system-scoped credentials in Warnings Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-46657 BR2023-0000-009680 SECURITY-2896 unclaimed
Non-constant time webhook token comparison in Gogs Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2023-46656 BR2023-0000-009681 SECURITY-2875 unclaimed
Non-constant time webhook token comparison in Multibranch Scan Webhook Trigger Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-46658 BR2023-0000-009682 SECURITY-2876 unclaimed
Non-constant time webhook token comparison in MSTeams Webhook Trigger Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-46660 BR2023-0000-009683 SECURITY-2879 unclaimed
Non-constant time webhook token hash comparison in Zanata Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-46650 BR2023-0000-009684 SECURITY-3246 unclaimed
Stored XSS vulnerability in GitHub Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2023-46659 BR2023-0000-009685 SECURITY-3247 unclaimed
Stored XSS vulnerability in Edgewall Trac Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.