Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2023-12-13

2023-12-13 Dec 13, 2023 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2023-12-13/. 12 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2023-12-13/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

11 lines
Showing 1–11 of 11
CVE-2023-50778 BR2023-0000-009660 SECURITY-3179 unclaimed
CSRF vulnerability and missing permission checks in PaaSLane Estimate Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-50776 BR2023-0000-009661 SECURITY-3182 unclaimed
Tokens stored and displayed in plain text by PaaSLane Estimate Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-50774 BR2023-0000-009662 SECURITY-3183 unclaimed
CSRF vulnerability in HTMLResource Plugin allows deleting arbitrary files
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-50772 BR2023-0000-009663 SECURITY-3184 unclaimed
Tokens stored and displayed in plain text by Dingding JSON Pusher Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-50768 BR2023-0000-009664 SECURITY-3203 unclaimed
CSRF vulnerability and missing permission checks in Nexus Platform Plugin allow capturing credentials
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-50766 BR2023-0000-009665 SECURITY-3204 unclaimed
CSRF vulnerability and missing permission checks in Nexus Platform Plugin allow XXE
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-50764 BR2023-0000-009666 SECURITY-3205 unclaimed
Arbitrary file deletion vulnerability in Scriptler Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-50765 BR2023-0000-009667 SECURITY-3206 unclaimed
Missing permission check in Scriptler Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2023-50771 BR2023-0000-009668 SECURITY-2979 unclaimed
Open redirect vulnerability in OpenId Connect Authentication Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-50775 BR2023-0000-009669 SECURITY-3092 unclaimed
CSRF vulnerability in Deployment Dashboard Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2023-50770 BR2023-0000-009670 SECURITY-3168 unclaimed
Password stored in a recoverable format by OpenId Connect Authentication Plugin
Credited as Steve Marlowe of Cisco ASIG