Publish Advisories

GHSA-3858-58w9-wpcg
GHSA-cqp7-hwm3-cfg7
GHSA-jcmg-9rw5-9rm2
GHSA-jp4r-pf5r-4wg8
GHSA-m46p-rp8x-x8c4
This commit is contained in:
advisory-database[bot]
2024-01-30 22:29:28 +00:00
parent 4325f2a214
commit 3dd23ef843
5 changed files with 124 additions and 20 deletions
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3858-58w9-wpcg",
"modified": "2022-05-13T01:31:34Z",
"modified": "2024-01-30T22:28:39Z",
"published": "2022-05-13T01:31:34Z",
"aliases": [
"CVE-2019-1003021"
],
"summary": "Jenkins OpenId Connect Authentication Plugin showed plain text client secret in configuration form",
"details": "An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.",
"severity": [
{
@@ -14,7 +15,28 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:oic-auth"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.5"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 1.4"
}
}
],
"references": [
{
@@ -31,8 +53,8 @@
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T22:28:39Z",
"nvd_published_at": "2019-02-06T16:29:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqp7-hwm3-cfg7",
"modified": "2022-05-13T01:31:34Z",
"modified": "2024-01-30T22:27:57Z",
"published": "2022-05-13T01:31:34Z",
"aliases": [
"CVE-2019-1003023"
],
"summary": "XSS vulnerability in Jenkins Warnings Next Generation Plugin",
"details": "A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourcePrinter.java, src/main/java/io/jenkins/plugins/analysis/core/util/Sanitizer.java, src/main/java/io/jenkins/plugins/analysis/warnings/DuplicateCodeScanner.java that allows attackers with the ability to control warnings parser input to have Jenkins render arbitrary HTML.",
"severity": [
{
@@ -14,7 +15,28 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "io.jenkins.plugins:warnings-ng"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.0"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 1.0.1"
}
}
],
"references": [
{
@@ -31,8 +53,8 @@
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T22:27:57Z",
"nvd_published_at": "2019-02-06T16:29:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jcmg-9rw5-9rm2",
"modified": "2022-05-13T01:30:26Z",
"modified": "2024-01-30T22:29:06Z",
"published": "2022-05-13T01:30:26Z",
"aliases": [
"CVE-2018-1000426"
],
"summary": "Stored XSS vulnerability in Jenkins Git Changelog Plugin",
"details": "A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the Git history parsed by the plugin to have Jenkins render arbitrary HTML on some pages.",
"severity": [
{
@@ -14,7 +15,28 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "de.wellnerbou.jenkins:git-changelog"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.7"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 2.6"
}
}
],
"references": [
{
@@ -35,8 +57,8 @@
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T22:28:55Z",
"nvd_published_at": "2019-01-09T23:29:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jp4r-pf5r-4wg8",
"modified": "2022-05-13T01:25:43Z",
"modified": "2024-01-30T22:27:38Z",
"published": "2022-05-13T01:25:43Z",
"aliases": [
"CVE-2019-1003080"
],
"summary": "CSRF vulnerability in Jenkins OpenShift Deployer Plugin",
"details": "A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers to initiate a connection to an attacker-specified server.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:openshift-deployer"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.2.0"
}
]
}
]
}
],
"references": [
{
@@ -39,8 +58,8 @@
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T22:27:17Z",
"nvd_published_at": "2019-04-04T16:29:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m46p-rp8x-x8c4",
"modified": "2022-05-13T01:25:16Z",
"modified": "2024-01-30T22:28:22Z",
"published": "2022-05-13T01:25:16Z",
"aliases": [
"CVE-2019-1003081"
],
"summary": "CSRF vulnerability in Jenkins OpenShift Deployer Plugin",
"details": "A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:openshift-deployer"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.2.0"
}
]
}
]
}
],
"references": [
{
@@ -39,8 +58,8 @@
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T22:28:13Z",
"nvd_published_at": "2019-04-04T16:29:00Z"
}
}