Publish Advisories

GHSA-7gqc-q9mc-6348
GHSA-39r8-4962-j7vg
GHSA-9pvw-8q92-hm9w
GHSA-rr3p-5fcf-v5m3
GHSA-3vcr-579j-4x48
GHSA-c7r5-cww9-64q6
This commit is contained in:
advisory-database[bot]
2024-01-30 23:14:01 +00:00
parent fed4eab174
commit feee82a420
6 changed files with 160 additions and 34 deletions
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7gqc-q9mc-6348",
"modified": "2023-04-21T18:30:23Z",
"modified": "2024-01-30T23:13:34Z",
"published": "2023-04-12T18:30:35Z",
"aliases": [
"CVE-2023-30532"
],
"summary": "Lack of authentication mechanism in Jenkins TurboScript Plugin webhook",
"details": "A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresponding to the attacker-specified repository.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkinsci.plugins.spoonscript:spoonscript"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.3"
}
]
}
]
}
],
"references": [
{
@@ -34,9 +53,9 @@
"cwe_ids": [
"CWE-862"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T23:13:34Z",
"nvd_published_at": "2023-04-12T18:15:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-39r8-4962-j7vg",
"modified": "2023-06-23T15:30:41Z",
"modified": "2024-01-30T23:12:41Z",
"published": "2023-06-14T15:30:37Z",
"aliases": [
"CVE-2023-35144"
],
"summary": "Stored XSS vulnerability in Jenkins Maven Repository Server Plugin",
"details": "Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "jenkins:repository"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.10"
}
]
}
]
}
],
"references": [
{
@@ -34,9 +53,9 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T23:12:41Z",
"nvd_published_at": "2023-06-14T13:15:12Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pvw-8q92-hm9w",
"modified": "2023-06-23T15:30:41Z",
"modified": "2024-01-30T23:12:52Z",
"published": "2023-06-14T15:30:37Z",
"aliases": [
"CVE-2023-35143"
],
"summary": "Stored XSS vulnerability in Jenkins Maven Repository Server Plugin",
"details": "Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in `pom.xml`.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "jenkins:repository"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.10"
}
]
}
]
}
],
"references": [
{
@@ -34,9 +53,9 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T23:12:52Z",
"nvd_published_at": "2023-06-14T13:15:11Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rr3p-5fcf-v5m3",
"modified": "2023-06-23T18:30:21Z",
"modified": "2024-01-30T23:13:05Z",
"published": "2023-06-14T15:30:37Z",
"aliases": [
"CVE-2023-35142"
],
"summary": "SSL/TLS certificate validation disabled by default in Jenkins Checkmarx Plugin",
"details": "Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.",
"severity": [
{
@@ -14,7 +15,28 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "com.checkmarx.jenkins:checkmarx"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2023.2.6"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 2022.4.3"
}
}
],
"references": [
{
@@ -34,9 +56,9 @@
"cwe_ids": [
"CWE-295"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T23:13:05Z",
"nvd_published_at": "2023-06-14T13:15:11Z"
}
}
@@ -1,17 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vcr-579j-4x48",
"modified": "2023-09-06T15:30:26Z",
"modified": "2024-01-30T23:11:51Z",
"published": "2023-09-06T15:30:26Z",
"aliases": [
"CVE-2023-41940"
],
"summary": "Stored XSS vulnerability in Jenkins TAP Plugin",
"details": "Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control TAP file contents.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.tap4j:tap"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.3"
}
]
}
]
}
],
"references": [
{
@@ -29,11 +51,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T23:11:51Z",
"nvd_published_at": "2023-09-06T13:15:11Z"
}
}
@@ -1,17 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7r5-cww9-64q6",
"modified": "2023-09-06T15:30:26Z",
"modified": "2024-01-30T23:12:08Z",
"published": "2023-09-06T15:30:26Z",
"aliases": [
"CVE-2023-41930"
],
"summary": "Path traversal in Jenkins Job Configuration History Plugin",
"details": "Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:jobConfigHistory"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1229.v3039470161a_d"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 1227.v7a"
}
}
],
"references": [
{
@@ -29,11 +54,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T23:12:08Z",
"nvd_published_at": "2023-09-06T13:15:09Z"
}
}