Publish Advisories

GHSA-25c5-58xw-hw5q
GHSA-cc55-c9j4-m7cx
GHSA-25c5-58xw-hw5q
GHSA-cc55-c9j4-m7cx
This commit is contained in:
advisory-database[bot]
2025-03-13 17:46:47 +00:00
parent 70d8186fc9
commit c0433a82db
4 changed files with 192 additions and 92 deletions
@@ -0,0 +1,100 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25c5-58xw-hw5q",
"modified": "2025-03-13T17:45:33Z",
"published": "2022-05-05T02:48:48Z",
"aliases": [
"CVE-2013-0330"
],
"summary": "Jenkins allows Remote Users to Build Arbitrary Jobs",
"details": "Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to build arbitrary jobs via unknown attack vectors.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.main:jenkins-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.481"
},
{
"fixed": "1.502"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.main:jenkins-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.480.3"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2013-0330"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=914878"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/jenkins"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20200229023853/http://www.securityfocus.com/bid/57994"
},
{
"type": "WEB",
"url": "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2013-0638.html"
},
{
"type": "WEB",
"url": "http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2013/02/21/7"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-03-13T17:45:33Z",
"nvd_published_at": "2013-03-19T14:55:00Z"
}
}
@@ -0,0 +1,92 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc55-c9j4-m7cx",
"modified": "2025-03-13T17:46:02Z",
"published": "2022-05-04T00:29:23Z",
"aliases": [
"CVE-2012-0325"
],
"summary": "Jenkins allows Cross-Site Scripting (XSS)",
"details": "Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0324.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.main:jenkins-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.425"
},
{
"fixed": "1.454"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.main:jenkins-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.424.5"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-0325"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/jenkins"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20200229025003/http://www.securityfocus.com/bid/52384"
},
{
"type": "WEB",
"url": "http://jvn.jp/en/jp/JVN79950061/index.html"
},
{
"type": "WEB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2012-000023"
},
{
"type": "WEB",
"url": "http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-03-05.cb"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2025-03-13T17:46:02Z",
"nvd_published_at": "2012-03-09T11:55:00Z"
}
}
@@ -1,49 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25c5-58xw-hw5q",
"modified": "2022-05-05T02:48:48Z",
"published": "2022-05-05T02:48:48Z",
"aliases": [
"CVE-2013-0330"
],
"details": "Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to build arbitrary jobs via unknown attack vectors.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2013-0330"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=914878"
},
{
"type": "WEB",
"url": "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2013-0638.html"
},
{
"type": "WEB",
"url": "http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2013/02/21/7"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/57994"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2013-03-19T14:55:00Z"
}
}
@@ -1,43 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc55-c9j4-m7cx",
"modified": "2022-05-04T00:29:23Z",
"published": "2022-05-04T00:29:23Z",
"aliases": [
"CVE-2012-0325"
],
"details": "Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0324.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-0325"
},
{
"type": "WEB",
"url": "http://jvn.jp/en/jp/JVN79950061/index.html"
},
{
"type": "WEB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2012-000023"
},
{
"type": "WEB",
"url": "http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-03-05.cb"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/52384"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2012-03-09T11:55:00Z"
}
}