Jenkins plugins security advisory

56 views
Skip to first unread message

Daniel Beck

unread,
Jul 27, 2022, 9:49:00 AM7/27/22
to Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities:

* Compuware ISPW Operations Plugin 1.0.9
* Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.13
* Compuware Topaz Utilities Plugin 1.0.9
* Compuware Xpediter Code Coverage Plugin 1.0.8
* Compuware zAdviser API Plugin 1.0.4
* Deployer Framework Plugin 86.v7b_a_4a_55b_f3ec
* External Monitor Job Type Plugin 192.ve979ca_8b_3ccd
* Git client Plugin 3.11.1
* Git Plugin 4.11.4
* GitHub Plugin 1.34.5
* HashiCorp Vault Plugin 355.v3b_38d767a_b_a_8
* Job Configuration History Plugin 1156.v536a_97b_8d649
* rhnpush-plugin Plugin 0.5.2
* rpmsign-plugin Plugin 0.5.1

Additionally, we announce unresolved security issues in the following plugins:

* Android Signing Plugin
* Buckminster Plugin
* CLIF Performance Testing Plugin
* Coverity Plugin
* Dynamic Extended Choice Parameter Plugin
* Files Found Trigger Plugin
* Google Cloud Backup Plugin
* HTTP Request Plugin
* Lucene-Search Plugin
* Maven Metadata Plugin for Jenkins CI server Plugin
* OpenShift Deployer Plugin
* Openstack Heat Plugin
* Repository Connector Plugin

Please see the advisory for more information:
https://www.jenkins.io/security/advisory/2022-07-27/
Reply all
Reply to author
Forward
0 new messages