From 62645eebc15cdd82264b92a7772a16ae6a75d421 Mon Sep 17 00:00:00 2001 From: Li-Wen Hsu Date: Wed, 28 Aug 2019 15:36:03 +0000 Subject: [PATCH] Document Jenkins Security Advisory 2019-08-28 Sponsored by: The FreeBSD Foundation --- security/vuxml/vuln.xml | 35 +++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index cd364c17bd83..35a80dd83832 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,41 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + jenkins -- multiple vulnerabilities + + + jenkins + 2.191 + + + jenkins-lts + 2.176.2 + + + + +

Jenkins Security Advisory:

+
+

Description

+
(Medium) SECURITY-1453 / CVE-2019-10383
+

Stored XSS vulnerability in update center

+
(High) SECURITY-1491 / CVE-2019-10384
+

CSRF protection tokens for anonymous users did not expire in some circumstances

+
+ +
+ + CVE-2019-10383 + CVE-2019-10384 + https://jenkins.io/security/advisory/2019-08-28/ + + + 2019-08-28 + 2019-08-28 + +
+ Mozilla -- Stored passwords in 'Saved Logins' can be copied without master password entry