diff --git a/advisories/unreviewed/2022/05/GHSA-3858-58w9-wpcg/GHSA-3858-58w9-wpcg.json b/advisories/github-reviewed/2022/05/GHSA-3858-58w9-wpcg/GHSA-3858-58w9-wpcg.json similarity index 60% rename from advisories/unreviewed/2022/05/GHSA-3858-58w9-wpcg/GHSA-3858-58w9-wpcg.json rename to advisories/github-reviewed/2022/05/GHSA-3858-58w9-wpcg/GHSA-3858-58w9-wpcg.json index de677a2a595..01959cfb2a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3858-58w9-wpcg/GHSA-3858-58w9-wpcg.json +++ b/advisories/github-reviewed/2022/05/GHSA-3858-58w9-wpcg/GHSA-3858-58w9-wpcg.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3858-58w9-wpcg", - "modified": "2022-05-13T01:31:34Z", + "modified": "2024-01-30T22:28:39Z", "published": "2022-05-13T01:31:34Z", "aliases": [ "CVE-2019-1003021" ], + "summary": "Jenkins OpenId Connect Authentication Plugin showed plain text client secret in configuration form", "details": "An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.", "severity": [ { @@ -14,7 +15,28 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:oic-auth" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.5" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 1.4" + } + } ], "references": [ { @@ -31,8 +53,8 @@ "CWE-200" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T22:28:39Z", "nvd_published_at": "2019-02-06T16:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-cqp7-hwm3-cfg7/GHSA-cqp7-hwm3-cfg7.json b/advisories/github-reviewed/2022/05/GHSA-cqp7-hwm3-cfg7/GHSA-cqp7-hwm3-cfg7.json similarity index 66% rename from advisories/unreviewed/2022/05/GHSA-cqp7-hwm3-cfg7/GHSA-cqp7-hwm3-cfg7.json rename to advisories/github-reviewed/2022/05/GHSA-cqp7-hwm3-cfg7/GHSA-cqp7-hwm3-cfg7.json index 195663cf842..d132fb2aaad 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqp7-hwm3-cfg7/GHSA-cqp7-hwm3-cfg7.json +++ b/advisories/github-reviewed/2022/05/GHSA-cqp7-hwm3-cfg7/GHSA-cqp7-hwm3-cfg7.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cqp7-hwm3-cfg7", - "modified": "2022-05-13T01:31:34Z", + "modified": "2024-01-30T22:27:57Z", "published": "2022-05-13T01:31:34Z", "aliases": [ "CVE-2019-1003023" ], + "summary": "XSS vulnerability in Jenkins Warnings Next Generation Plugin", "details": "A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourcePrinter.java, src/main/java/io/jenkins/plugins/analysis/core/util/Sanitizer.java, src/main/java/io/jenkins/plugins/analysis/warnings/DuplicateCodeScanner.java that allows attackers with the ability to control warnings parser input to have Jenkins render arbitrary HTML.", "severity": [ { @@ -14,7 +15,28 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "io.jenkins.plugins:warnings-ng" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.0.0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 1.0.1" + } + } ], "references": [ { @@ -31,8 +53,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T22:27:57Z", "nvd_published_at": "2019-02-06T16:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-jcmg-9rw5-9rm2/GHSA-jcmg-9rw5-9rm2.json b/advisories/github-reviewed/2022/05/GHSA-jcmg-9rw5-9rm2/GHSA-jcmg-9rw5-9rm2.json similarity index 64% rename from advisories/unreviewed/2022/05/GHSA-jcmg-9rw5-9rm2/GHSA-jcmg-9rw5-9rm2.json rename to advisories/github-reviewed/2022/05/GHSA-jcmg-9rw5-9rm2/GHSA-jcmg-9rw5-9rm2.json index 8d2cfcbfb52..13c570f7700 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcmg-9rw5-9rm2/GHSA-jcmg-9rw5-9rm2.json +++ b/advisories/github-reviewed/2022/05/GHSA-jcmg-9rw5-9rm2/GHSA-jcmg-9rw5-9rm2.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jcmg-9rw5-9rm2", - "modified": "2022-05-13T01:30:26Z", + "modified": "2024-01-30T22:29:06Z", "published": "2022-05-13T01:30:26Z", "aliases": [ "CVE-2018-1000426" ], + "summary": "Stored XSS vulnerability in Jenkins Git Changelog Plugin", "details": "A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the Git history parsed by the plugin to have Jenkins render arbitrary HTML on some pages.", "severity": [ { @@ -14,7 +15,28 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "de.wellnerbou.jenkins:git-changelog" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.7" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2.6" + } + } ], "references": [ { @@ -35,8 +57,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T22:28:55Z", "nvd_published_at": "2019-01-09T23:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-jp4r-pf5r-4wg8/GHSA-jp4r-pf5r-4wg8.json b/advisories/github-reviewed/2022/05/GHSA-jp4r-pf5r-4wg8/GHSA-jp4r-pf5r-4wg8.json similarity index 66% rename from advisories/unreviewed/2022/05/GHSA-jp4r-pf5r-4wg8/GHSA-jp4r-pf5r-4wg8.json rename to advisories/github-reviewed/2022/05/GHSA-jp4r-pf5r-4wg8/GHSA-jp4r-pf5r-4wg8.json index e4b531c2217..30a591836a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp4r-pf5r-4wg8/GHSA-jp4r-pf5r-4wg8.json +++ b/advisories/github-reviewed/2022/05/GHSA-jp4r-pf5r-4wg8/GHSA-jp4r-pf5r-4wg8.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jp4r-pf5r-4wg8", - "modified": "2022-05-13T01:25:43Z", + "modified": "2024-01-30T22:27:38Z", "published": "2022-05-13T01:25:43Z", "aliases": [ "CVE-2019-1003080" ], + "summary": "CSRF vulnerability in Jenkins OpenShift Deployer Plugin", "details": "A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers to initiate a connection to an attacker-specified server.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:openshift-deployer" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.2.0" + } + ] + } + ] + } ], "references": [ { @@ -39,8 +58,8 @@ "CWE-352" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T22:27:17Z", "nvd_published_at": "2019-04-04T16:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-m46p-rp8x-x8c4/GHSA-m46p-rp8x-x8c4.json b/advisories/github-reviewed/2022/05/GHSA-m46p-rp8x-x8c4/GHSA-m46p-rp8x-x8c4.json similarity index 67% rename from advisories/unreviewed/2022/05/GHSA-m46p-rp8x-x8c4/GHSA-m46p-rp8x-x8c4.json rename to advisories/github-reviewed/2022/05/GHSA-m46p-rp8x-x8c4/GHSA-m46p-rp8x-x8c4.json index 9928c8f655f..fd291944749 100644 --- a/advisories/unreviewed/2022/05/GHSA-m46p-rp8x-x8c4/GHSA-m46p-rp8x-x8c4.json +++ b/advisories/github-reviewed/2022/05/GHSA-m46p-rp8x-x8c4/GHSA-m46p-rp8x-x8c4.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-m46p-rp8x-x8c4", - "modified": "2022-05-13T01:25:16Z", + "modified": "2024-01-30T22:28:22Z", "published": "2022-05-13T01:25:16Z", "aliases": [ "CVE-2019-1003081" ], + "summary": "CSRF vulnerability in Jenkins OpenShift Deployer Plugin", "details": "A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:openshift-deployer" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.2.0" + } + ] + } + ] + } ], "references": [ { @@ -39,8 +58,8 @@ "CWE-862" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T22:28:13Z", "nvd_published_at": "2019-04-04T16:29:00Z" } } \ No newline at end of file