Jenkins plugins security advisory

77 views
Skip to first unread message

Daniel Beck

unread,
Oct 19, 2022, 11:08:01 AM10/19/22
to Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities:

* Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.13
* Compuware Topaz Utilities Plugin 1.0.9
* Compuware Xpediter Code Coverage Plugin 1.0.8
* Contrast Continuous Application Security Plugin 3.10
* Generic Webhook Trigger Plugin 1.84.2
* GitLab Plugin 1.5.36
* Job Import Plugin 3.6
* Katalon Plugin 1.0.33 and 1.0.34
* Mercurial Plugin 1260.vdfb_723cdcc81
* NUnit Plugin 0.28
* Pipeline: Deprecated Groovy Libraries Plugin 588.v576c103a_ff86
* Pipeline: Groovy Libraries Plugin 613.v9c41a_160233f
* Pipeline: Groovy Plugin 2803.v1a_f77ffcc773
* Pipeline: Input Step Plugin 456.vd8a_957db_5b_e9
* Pipeline: Stage View Plugin 2.27
* Pipeline: Supporting APIs Plugin 839.v35e2736cfd5c
* REPO Plugin 1.16.0
* Script Security Plugin 1184.v85d16b_d851b_3
* Tuleap Git Branch Source Plugin 3.2.5

Additionally, we announce unresolved security issues in the following plugins:

* 360 FireLine Plugin
* Compuware Strobe Measurement Plugin
* Compuware Topaz for Total Test Plugin
* Custom Checkbox Parameter Plugin
* NeuVector Vulnerability Scanner Plugin
* S3 Explorer Plugin
* ScreenRecorder Plugin
* XFramium Builder Plugin

Please see the advisory for more information:
https://www.jenkins.io/security/advisory/2022-10-19/

Reply all
Reply to author
Forward
0 new messages