[oss-security] Terrapin vulnerability in Jenkins CLI client

2024-04-17 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. The following releases contain fixes for security vulnerabilities: * Jenkins 2.452 * Jenkins LTS 2.440.3 Summaries of the vulnerabilities are below. More deta

[oss-security] Multiple vulnerabilities in Jenkins plugins

2024-05-02 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. The following releases contain fixes for security vulnerabilities: * Git server Plugin 117.veb_68868fa_027 * Script Security Plugin 1336.vf33a_a_9863911 Addit

[oss-security] Multiple vulnerabilities in Jenkins plugins

2024-06-26 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. The following releases contain fixes for security vulnerabilities: * Bitbucket Branch Source Plugin 887.va_d359b_3d2d8d * Plain Credentials Plugin 183.va_de8f1

[oss-security] Multiple vulnerabilities in Jenkins

2024-08-07 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. The following releases contain fixes for security vulnerabilities: * Jenkins 2.471 * Jenkins LTS 2.452.4 and 2.462.1 Summaries of the vulnerabilities are bel

[oss-security] Multiple vulnerabilities in Jenkins plugins

2024-11-13 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. The following releases contain fixes for security vulnerabilities: * Authorize Project Plugin 1.8.0 * IvyTrigger Plugin 1.02 * OpenId Connect Authentication Pl

[oss-security] Multiple vulnerabilities in Jenkins and Jenkins plugins

2024-10-02 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. The following releases contain fixes for security vulnerabilities: * Jenkins 2.479 * Jenkins LTS 2.462.3 * Credentials Plugin 1381.v2c3a_12074da_b_ * OpenId Co

[oss-security] Multiple vulnerabilities in Jenkins and Jenkins plugins

2024-11-27 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. The following releases contain fixes for security vulnerabilities: * Jenkins 2.487 * Jenkins LTS 2.479.2 * Filesystem List Parameter Plugin 0.0.15 * Simple Que

[oss-security] Vulnerabilities in Jenkins Docker images

2025-04-10 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. Summaries of the vulnerabilities are below. More details, severity, and attribution can be found here: https://www.jenkins.io/security/advisory/2025-04-10/ We

[oss-security] Multiple vulnerabilities in Jenkins plugins

2025-03-19 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. The following releases contain fixes for security vulnerabilities: * EDDSA API Plugin 0.3.0.1-16.vcb_4a_98a_3531c * Zoho QEngine Plugin 1.0.31.v4a_b_1db_6d6a_f

[oss-security] Vulnerability in Jenkins Gatling Plugin

2025-06-06 Thread Daniel Beck
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software. We announce unresolved security issues in the following plugins: * Gatling Plugin Summaries of the vulnerabilities are below. More details, severity, and attr