Jenkins plugins security advisory

2024-05-02 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Git server Plugin 117.veb_68868fa_027 * Script Security Plugin 1336.vf33a_a_9863911 Additionally, we announce unresolved security issues in the following plugins: * Subversion Partial Release Manager Plugin *

Jenkins security advisory

2024-03-20 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.444 * Jenkins LTS 2.440.2 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2024-03-20/ -- You received this message because you are subscribed to the Google Groups

Jenkins plugins security advisory

2024-03-06 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * AppSpider Plugin 1.0.17 * Bitbucket Branch Source Plugin 871.v28d74e8b_4226 * Delphix Plugin 3.0.2 and 3.1.1 * HTML Publisher Plugin 1.32.1 * MQ Notifier Plugin 1.4.1 * OWASP Dependency-Check Plugin 5.4.6 * Trilead

Jenkins plugins security advisory pre-announcement

2024-03-04 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, March 6. The highest severity is 'High' and affects plugins installed on between 25% and 75% of known instances. The most popular included plugins are installed on more than 75% of known instances and have

Jenkins security advisory

2024-01-24 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.442 * Jenkins LTS 2.426.3 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Git server Plugin 99.101.v720e86326c09 * GitLab Branch Source Plugin 688.v5fa_356ee8520 * Matrix

Jenkins plugins security advisory

2023-12-13 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Analysis Model API Plugin 11.13.0 * Nexus Platform Plugin 3.18.1-01 * Scriptler Plugin 344.v5a_ddb_5f9e685 Additionally, we announce unresolved security issues in the following plugins: * Deployment Dashboard

Jenkins plugins security advisory

2023-11-29 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Google Compute Engine Plugin 4.551.v5a_4dc98f6962 * Jira Plugin 3.12 * MATLAB Plugin 2.11.1 * NeuVector Vulnerability Scanner Plugin 2.2 Please see the advisory for more information:

Jenkins plugins security advisory

2023-10-25 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * CloudBees CD Plugin 1.1.33 * GitHub Plugin 1.37.3.1 * lambdatest-automation Plugin 1.20.10 and 1.21.0 * Warnings Plugin 10.5.1 Additionally, we announce unresolved security issues in the following plugins: *

Jenkins security advisory

2023-10-18 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.428 * Jenkins LTS 2.414.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2023-10-18/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory

2023-09-20 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.424 * Jenkins LTS 2.414.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Build Failure Analyzer Plugin 2.4.2 Please see the advisory for more information:

Jenkins security advisory pre-announcement

2023-09-14 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.414.2) on Wednesday, September 20. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

Jenkins plugins security advisory

2023-09-06 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Azure AD Plugin 397.v907382dd9b_98 and 378.380.v545b_1154b_3fb_ * Bitbucket Push and Pull Request Plugin 2.8.4 * Google Login Plugin 1.8 * Job Configuration History Plugin 1229.v3039470161a_d * Pipeline Maven

Jenkins plugins security advisory pre-announcement

2023-09-04 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, September 6. The highest severity is 'High'. The most popular included plugin is installed on between 10% and 25% of known instances. The advisory includes issues that will be published without a fix as

Jenkins plugins security advisory

2023-08-16 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Blue Ocean Plugin 1.27.5.1 * Config File Provider Plugin 953.v0432a_802e4d2 * Delphix Plugin 3.0.3 * Flaky Test Handler Plugin 1.2.3 * Folders Plugin 6.848.ve3b_fd7839a_81 * Fortify Plugin 22.2.39 * NodeJS Plugin

Jenkins plugins security advisory pre-announcement

2023-08-15 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, August 16. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins security advisory

2023-07-26 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.416 * Jenkins LTS 2.401.3 The following Jenkins plugin updates contain fixes for security vulnerabilities: * GitLab Authentication Plugin 1.18 * Gradle Plugin 2.8.1 * Qualys Web App Scanning Connector Plugin

Jenkins security advisory pre-announcement

2023-07-20 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.401.3) on Wednesday, July 26. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to provide

Jenkins plugins security advisory

2023-07-12 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Active Directory Plugin 2.30.1 * Datadog Plugin 5.4.2 * External Monitor Job Type Plugin 207.v98a_a_37a_85525 * mabl Plugin 0.0.47 * OpenShift Login Plugin 1.1.0.230.v5d7030b_f5432 * Oracle Cloud Infrastructure

Jenkins plugins security advisory pre-announcement

2023-07-11 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, July 12. The highest severity is 'High'. The most popular included plugin is installed on between 25% and 75% of known instances. The advisory includes issues that will be published without a fix as outlined

Jenkins security advisory

2023-06-14 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.400 (released 2023-04-11) * Jenkins LTS 2.401.1 (released 2023-05-31) The following Jenkins plugin updates contain fixes for security vulnerabilities: * Checkmarx Plugin 2023.2.6 * Dimensions Plugin 0.9.3.1 *

Jenkins security advisory pre-announcement

2023-06-13 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins and Jenkins plugins on Wednesday, June 14. It announces a security vulnerability that is already fixed in the latest weekly releases and Jenkins LTS 2.401.1. Its severity is 'High'. Additionally, it announces security issues in

Jenkins plugins security advisory

2023-05-16 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Ansible Plugin 205.v4cb_c48657c21 * AppSpider Plugin 1.0.16 * Azure VM Agents Plugin 853.v4a_1a_dd947520 * CAS Plugin 1.6.3 * Code Dx Plugin 4.0.0 * Email Extension Plugin 2.96.1 * File Parameter Plugin

Jenkins plugins security advisory pre-announcement

2023-05-15 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, May 16. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins plugins security advisory

2023-04-12 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Azure Key Vault Plugin 188.vf46b_7fa_846a_1 * Kubernetes Plugin 3910.ve59cec5e33ea_ Additionally, we announce unresolved security issues in the following plugins: * Assembla merge request builder Plugin * Consul

Jenkins plugins security advisory pre-announcement

2023-04-11 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, April 12. The highest severity is 'High' and affects plugins installed on less than 1% of known instances. The most popular included plugins are installed on between 10% and 25% of known instances and have

Jenkins plugins security advisory

2023-03-21 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * JaCoCo Plugin 3.3.2.1 * OctoPerf Load Testing Plugin 4.5.1, 4.5.2, and 4.5.3 * Pipeline Aggregator View Plugin 1.14 * Role-based Authorization Strategy Plugin 587.588.v850a_20a_30162 Additionally, we announce

Jenkins plugins security advisory pre-announcement

2023-03-20 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, March 21. The highest severity is 'High' and affects plugins installed on between 3% and 10% of known instances. The most popular included plugins are installed on between 25% and 75% of known instances and

Jenkins security advisory

2023-03-08 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.394 * Jenkins LTS 2.375.4 and 2.387.1 The following Jenkins component updates contain fixes for security vulnerabilities: * update-center2 3.15 Please see the advisory for more information:

Jenkins security advisory pre-announcement

2023-03-03 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly, LTS 2.375.4, and LTS 2.387.1) on Wednesday, March 8. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same

Jenkins plugins security advisory

2023-02-15 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Azure Credentials Plugin 254.v64da_8176c83a * Email Extension Plugin 2.93.1 * JUnit Plugin 1166.1168.vd6b_8042a_06de * Pipeline: Build Step Plugin 2.18.1 * Synopsys Coverity Plugin 3.0.3 Please see the advisory

Jenkins plugins security advisory pre-announcement

2023-02-14 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, February 15. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. This affects only Jenkins plugins, there will be no corresponding security

Jenkins security advisory

2023-02-09 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins deliverables contain fixes for security vulnerabilities: * Jenkins controller and agent Docker images Please see the advisory for more information: https://www.jenkins.io/security/advisory/2023-02-09/ -- You received this message because you are subscribed to the Google

Jenkins plugins security advisory

2023-01-24 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Azure AD Plugin 306.va_7083923fd50 * Bitbucket OAuth Plugin 0.13 * Gerrit Trigger Plugin 2.38.1 * Kubernetes Credentials Provider Plugin 1.209.v862c6e5fb_1ef * OpenId Connect Authentication Plugin 2.5 * Orka by

Jenkins plugins security advisory pre-announcement

2023-01-23 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, January 24. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins plugins security advisory

2022-12-07 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Checkmarx Plugin 2022.4.3 * Custom Build Properties Plugin 2.82.v16d5b_d3590c7 * Gitea Plugin 1.4.5 * Google Login Plugin 1.7 * Plot Plugin 2.1.12 * Spring Config Plugin 2.0.1 Additionally, we announce unresolved

Jenkins plugins security advisory pre-announcement

2022-12-06 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, December 7. The highest severity is 'High'. The most popular included plugin is installed on between 1% and 3% of known instances. The advisory includes issues that will be published without a fix as outlined

Jenkins plugins security advisory

2022-11-15 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * CloudBees Docker Hub/Registry Notification Plugin 2.6.2.1 * JUnit Plugin 1160.vf1f01a_a_ea_b_7f * Naginator Plugin 1.18.2 * NS-ND Integration Performance Publisher Plugin 4.8.0.146 * Pipeline Utility Steps Plugin

Jenkins plugins security advisory pre-announcement

2022-11-14 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, November 15. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins plugins security advisory

2022-10-19 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.13 * Compuware Topaz Utilities Plugin 1.0.9 * Compuware Xpediter Code Coverage Plugin 1.0.8 * Contrast Continuous Application Security Plugin

Jenkins plugins security advisory pre-announcement

2022-10-18 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, October 19. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins security advisory

2022-09-21 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.370 [see footnote 1] The following Jenkins plugin updates contain fixes for security vulnerabilities: * Anchore Container Image Scanner Plugin 1.0.25 * Compuware Common Configuration Plugin 1.0.15 * NS-ND

Jenkins plugins security advisory pre-announcement

2022-09-20 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, September 21. The highest severity is 'High'. The most popular included plugin is installed on less than 1% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins security advisory

2022-09-09 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.263 * Jenkins LTS 2.361.1 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2022-09-09/ -- You received this message because you are subscribed to the Google Groups

Jenkins plugins security advisory pre-announcement

2022-08-22 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, August 23. The highest severity is 'High' and affects plugins installed on between 10% and 25% of known instances. The most popular included plugins are installed on more than 75% of known instances and have

Jenkins plugins security advisory

2022-07-27 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Compuware ISPW Operations Plugin 1.0.9 * Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.13 * Compuware Topaz Utilities Plugin 1.0.9 * Compuware Xpediter Code Coverage Plugin 1.0.8 * Compuware

Jenkins plugins security advisory pre-announcement

2022-07-26 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, July 27. The highest severity is 'High' and affects plugins installed on between 1% and 3% of known instances. The most popular included plugins are installed on more than 75% of known instances and have

Jenkins plugins security advisory

2022-06-30 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * GitLab Plugin 1.5.35 * requests-plugin Plugin 2.2.17 * TestNG Results Plugin 555.va0d5f66521e3 * XebiaLabs XL Release Plugin 22.0.1 Additionally, we announce unresolved security issues in the following plugins: *

Jenkins plugins security advisory pre-announcement

2022-06-29 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Thursday, June 30. The highest severity is 'High'. The most popular included plugin is installed on between 10% and 25% of known instances. The advisory includes issues that will be published without a fix as outlined

Jenkins security advisory

2022-06-22 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.356 * Jenkins LTS 2.332.4 and 2.346.1 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Embeddable Build Status Plugin 2.0.4 * Hidden Parameter Plugin 0.0.5 * JUnit Plugin

Jenkins security advisory pre-announcement

2022-06-15 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly, LTS 2.332.4, and LTS 2.346.1) on Wednesday, June 22. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same

Jenkins plugins security advisory

2022-05-17 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Application Detector Plugin 1.0.9 * Blue Ocean Plugin 1.25.4 * Git Plugin 4.11.2 * GitLab Plugin 1.5.32 * Mercurial Plugin 2.16.1 * Multiselect parameter Plugin 1.4 * Pipeline SCM API for Blue Ocean Plugin 1.25.4

Jenkins plugins security advisory pre-announcement

2022-05-12 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, May 17. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. This affects only Jenkins plugins, there will be no corresponding security update for

Jenkins plugins security advisory

2022-04-12 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Credentials Plugin 1112.vc87b_7a_3597f6, 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1 * CVS Plugin 2.19.1 * Gerrit Trigger Plugin 2.35.3 * Git Parameter Plugin 0.9.16 * Google Compute Engine

Jenkins plugins security advisory pre-announcement

2022-04-08 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, April 12. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. This affects only Jenkins plugins, there will be no corresponding security update

Jenkins plugins security advisory

2022-03-29 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Bitbucket Server Integration Plugin 3.2.0 * Continuous Integration with Toad Edge Plugin 2.4 * Flaky Test Handler Plugin 1.2.2 * instant-messaging Plugin 1.42 * JiraTestResultReporter Plugin 166.v0cc6208295b5 *

Jenkins plugins security advisory pre-announcement

2022-03-28 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, March 29. The highest severity is 'High'. The most popular included plugin is installed on between 1% and 3% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins plugins security advisory

2022-03-15 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * CloudBees AWS Credentials Plugin 191.vcb_f183ce58b_9 * Dashboard View Plugin 2.18.1 * Favorite Plugin 2.4.1 * Folder-based Authorization Strategy Plugin 1.4 * Parameterized Trigger Plugin 2.43.1 * Semantic

Jenkins plugins security advisory pre-announcement

2022-03-14 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, March 15. The highest severity is 'High'. The most popular included plugin is installed on between 25% and 75% of known instances. The advisory includes issues that will be published without a fix as outlined

Jenkins plugins security advisory pre-announcement

2022-02-14 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, February 15. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins security advisory

2022-02-09 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.334 * Jenkins LTS 2.319.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2022-02-09/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory pre-announcement

2022-02-07 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.319.3) on Wednesday, February 9. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to

Jenkins security advisory pre-announcement

2022-01-05 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.319.2) on Wednesday, January 12. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to

Jenkins plugins security advisory

2021-11-12 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Active Choices Plugin 2.5.7 * Scriptler Plugin 3.4 Additionally, we announce unresolved security issues in the following plugins: * OWASP Dependency-Check Plugin * Performance Plugin * pom2config Plugin * Squash

Jenkins plugins security advisory pre-announcement

2021-11-11 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Friday, November 12. The highest severity is 'High'. The most popular included plugin is installed on between 3% and 10% of known instances. The advisory includes issues that will be published without a fix as outlined

Jenkins security advisory

2021-11-04 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.319 * Jenkins LTS 2.303.3 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Subversion Plugin 2.15.1 Please see the advisory for more information:

Jenkins security advisory pre-announcement

2021-11-01 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.303.3) on Thursday, November 4. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Critical". The security advisory will be issued at the same time to

Jenkins security advisory pre-announcement

2021-10-04 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.303.2) on Wednesday, October 6. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to

Jenkins plugins security advisory

2021-08-31 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Azure AD Plugin 180.v8b1e80e6f242 * Code Coverage API Plugin 1.4.1 * Nested View Plugin 1.21 * Nomad Plugin 0.7.5 * SAML Plugin 2.0.8 Please see the advisory for more information:

Jenkins plugins security advisory pre-announcement

2021-08-26 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, August 31. The highest severity is 'High'. The most popular included plugin is installed on between 3% and 10% of known instances. This affects only Jenkins plugins, there will be no corresponding security

Jenkins security advisory

2021-06-30 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.300 * Jenkins LTS 2.289.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * CAS Plugin 1.6.1 * requests-plugin 2.2.7, 2.2.8, and 2.2.13 * Selenium HTML report Plugin 1.1

Jenkins security advisory pre-announcement

2021-06-23 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.289.2) on Wednesday, June 30. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to provide

Jenkins plugins security advisory

2021-06-18 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Generic Webhook Trigger Plugin 1.74 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-06-18/ -- You received this message because you are subscribed to the Google Groups

Jenkins plugins security advisory

2021-06-16 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Scriptler Plugin 3.2 and 3.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-06-16/ -- You received this message because you are subscribed to the Google Groups

Jenkins plugins security advisory

2021-06-10 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Kiuwan Plugin 1.6.1 * Kubernetes CLI Plugin 1.10.1 * XebiaLabs XL Deploy Plugin 10.0.2 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-06-10/ -- You received this

Jenkins plugins security advisory

2021-05-25 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Filesystem Trigger Plugin 0.41 * Markdown Formatter Plugin 0.2.0 * Nuget Plugin 1.1 * URLTrigger Plugin 0.49 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-05-25/ --

Jenkins plugins security advisory

2021-05-11 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Credentials Plugin 2.3.19 * Dashboard View Plugin 2.16 * P4 Plugin 1.11.5 * S3 publisher Plugin 0.11.7 * Xcode integration Plugin 2.0.15 * Xray - Test Management for Jira Plugin 2.4.1 Please see the advisory for

Jenkins plugins security advisory pre-announcement

2021-05-07 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, May 11. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. This affects only Jenkins plugins, there will be no corresponding security update for

Jenkins plugins security advisory

2021-04-21 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * CloudBees CD Plugin 1.1.22 * Config File Provider Plugin 3.7.1 * Templating Engine Plugin 2.2 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-04-21/ -- You received

Jenkins plugins security advisory pre-announcement

2021-04-20 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, April 21. The highest severity is 'High'. The most popular included plugin is installed on between 25% and 75% of known instances. This affects only Jenkins plugins, there will be no corresponding security

Jenkins security advisory

2021-04-20 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.286 * Jenkins LTS 2.277.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-04-20/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory

2021-04-07 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.287 * Jenkins LTS 2.277.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Micro Focus Application Automation Tools Plugin 6.8 * promoted builds Plugin 3.9.1 Please see the

Jenkins security advisory pre-announcement

2021-03-31 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.277.2) on Wednesday, April 7. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to

Jenkins plugins security advisory

2021-03-30 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Build With Parameters Plugin 1.5.1 * Cloud Statistics Plugin 0.27 * Extra Columns Plugin 1.23 * Jabber (XMPP) notifier and control Plugin 1.42 * OWASP Dependency-Track Plugin 3.1.1 * REST List Parameter Plugin

Jenkins plugins security advisory pre-announcement

2021-03-26 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, March 30. The highest severity is 'High'. The most popular included plugin is installed on between 3% and 10% of known instances. The advisory includes issues that will be published without a fix as outlined at

Jenkins plugins security advisory

2021-03-18 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * CloudBees AWS Credentials Plugin 1.28.1 * Libvirt Agents Plugin 1.9.1 * Matrix Authorization Strategy Plugin 2.6.6 * Role-based Authorization Strategy Plugin 3.1.1 * Warnings Next Generation Plugin 8.5.0 Please

Jenkins plugins security advisory pre-announcement

2021-03-16 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Thursday, March 18. The highest severity is 'Medium'. The most popular included plugin is installed on more than 75% of known instances. This affects only Jenkins plugins, there will be no corresponding security update

Jenkins plugins security advisory

2021-02-24 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Active Choices Plugin 2.5.3 * Artifact Repository Parameter Plugin 1.0.1 * Claim Plugin 2.18.2 * Configuration Slicing Plugin 1.52 * Repository Connector Plugin 2.0.3 * Support Core Plugin 2.72.1 Please see the

Jenkins plugins security advisory pre-announcement

2021-02-22 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, February 24. The highest severity is 'High'. The most popular included plugin is installed on between 3% and 10% of known instances. This affects only Jenkins plugins, there will be no corresponding security

Jenkins security advisory

2021-02-19 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.280 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-02-19/ -- You received this message because you are subscribed to the Google Groups "Jenkins Advisories" group.

Jenkins security advisory

2021-01-26 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.276 * Jenkins LTS 2.263.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-01-26/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory

2021-01-13 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.275 * Jenkins LTS 2.263.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Bumblebee HP ALM Plugin 4.1.6 * TICS Plugin 2020.3.0.7 * TraceTronic ECU-TEST Plugin 2.24 Please

Jenkins security advisory pre-announcement

2021-01-07 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.263.2) on Wednesday, January 13. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

Jenkins security advisory

2020-12-03 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Chaos Monkey Plugin 0.4 and 0.4.1 * CVS Plugin 2.17 * Plugin Installation Manager Tool 2.2.0 * Shelve Project Plugin 3.1 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2020-12-03/?

Jenkins security advisory pre-announcement

2020-12-02 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins and other components on Thursday, December 3. The highest severity is 'High'. The most popular included plugin is installed on between 10% and 25% of known instances. -- You received this message because you are

Jenkins plugins security advisory

2020-11-04 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Active Directory Plugin 2.20 * Ansible Plugin 1.1 * AppSpider Plugin 1.0.13 * AWS Global Configuration Plugin 1.6 * Azure Key Vault Plugin 2.1 * Kubernetes Plugin 1.27.4 * Mercurial Plugin 2.12 * SQLPlus Script

Jenkins plugins security advisory pre-announcement

2020-11-02 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, November 4. The highest severity is 'Critical'. The most popular included plugin is installed on between 10% and 25% of known instances. The advisory includes issues that will be published without a fix as

Jenkins plugins security advisory

2020-10-08 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Active Choices Plugin 2.5 * Audit Trail Plugin 3.7 * couchdb-statistics Plugin 0.4 * Role-based Authorization Strategy Plugin 3.1 Additionally, we announce unresolved security issues in the following plugins: *

Jenkins plugins security advisory pre-announcement

2020-10-06 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Thursday, October 8. The highest severity is 'High'. The most popular included plugin is installed on between 25% and 75% of known instances. The advisory includes issues that will be published without a fix as outlined

Jenkins plugins security advisory

2020-09-23 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Implied Labels Plugin 0.7 * Liquibase Runner Plugin 1.4.8 * Lockable Resources Plugin 2.9 * Script Security Plugin 1.75 * Warnings Plugin 5.0.2 Please see the advisory for more information:

Jenkins plugins security advisory pre-announcement

2020-09-18 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, September 23. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. This affects only Jenkins plugins, there will be no corresponding security

  1   2   >