FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

jenkins -- multiple vulnerabilities

Affected packages
jenkins <= 2.196
jenkins-lts <= 2.176.3

Details

VuXML ID 9720bb39-f82a-402f-9fe4-e2c875bdda83
Discovery 2019-09-25
Entry 2019-09-25

Jenkins Security Advisory:

Description

(Medium) SECURITY-1498 / CVE-2019-10401

Stored XSS vulnerability in expandable textbox form control

(Medium) SECURITY-1525 / CVE-2019-10402

XSS vulnerability in combobox form control

(Medium) SECURITY-1537 (1) / CVE-2019-10403

Stored XSS vulnerability in SCM tag action tooltip

(Medium) SECURITY-1537 (2) / CVE-2019-10404

Stored XSS vulnerability in queue item tooltip

(Medium) SECURITY-1505 / CVE-2019-10405

Diagnostic web page exposed Cookie HTTP header

(Medium) SECURITY-1471 / CVE-2019-10406

XSS vulnerability in Jenkins URL setting

References

CVE Name CVE-2019-10401
CVE Name CVE-2019-10402
CVE Name CVE-2019-10403
CVE Name CVE-2019-10404
CVE Name CVE-2019-10405
CVE Name CVE-2019-10406
URL https://jenkins.io/security/advisory/2019-09-25/