Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2024-03-06

2024-03-06 Mar 6, 2024 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2024-03-06/. 15 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2024-03-06/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

13 lines
Showing 1–13 of 13
CVE-2024-28152 BR2024-0000-009622 SECURITY-3300 unclaimed
Incorrect trust policy behavior for pull requests from forks in Bitbucket Branch Source Plugin
Credited as Anders Hammar
CVE-2024-2215 BR2024-0000-009623 SECURITY-3200 unclaimed
CSRF vulnerability and missing permission check in docker-build-step Plugin
Credited as Andrea Chiera, CloudBees, Inc.
CVE-2024-28161 BR2024-0000-009624 SECURITY-3215 unclaimed
SSL/TLS certificate validation disabled by default in Delphix Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2024-28156 BR2024-0000-009625 SECURITY-3280 unclaimed
Stored XSS vulnerability in Build Monitor View Plugin
Credited as Daniel Beck, CloudBees, Inc.
CVE-2024-28155 BR2024-0000-009626 SECURITY-3144 unclaimed
Missing permission checks in AppSpider Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2024-28149 BR2024-0000-009627 SECURITY-3301 unclaimed
Improper input sanitization in HTML Publisher Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2024-28150 BR2024-0000-009628 SECURITY-3302 unclaimed
Stored XSS vulnerability in HTML Publisher Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2024-28151 BR2024-0000-009629 SECURITY-3303 unclaimed
Path traversal vulnerability in HTML Publisher Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2024-28158 BR2024-0000-009630 SECURITY-3325 unclaimed
CSRF vulnerability and missing permission checks in Subversion Partial Release Manager Plugin
Credited as Wadeck Follonier, CloudBees, Inc.
CVE-2024-28160 BR2024-0000-009631 SECURITY-3248 unclaimed
Stored XSS vulnerability in iceScrum Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2024-28157 BR2024-0000-009632 SECURITY-3249 unclaimed
Stored XSS vulnerability in GitBucket Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2024-28162 BR2024-0000-009633 SECURITY-3330 unclaimed
Improper SSL/TLS certificate validation in Delphix Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2024-28153 BR2024-0000-009634 SECURITY-3344 unclaimed
Stored XSS vulnerability in OWASP Dependency-Check Plugin
Credited as tkmwrbl