Security advisory pre-announcement

2017-01-25 Thread Daniel Beck
We will publish new Jenkins releases (mainline and 2.32.2 LTS) on Wednesday Feb 1. These releases will contain fixes for security issues found in current versions of Jenkins. The security advisory will be issued at the same time to provide further information. -- You received this message

Jenkins plugins security advisory

2017-03-20 Thread Daniel Beck
The following plugin updates have been released to fix security vulnerabilities: - Active Directory 2.3 - Distributed Fork 1.6.0 - Email-ext 2.57.1 - Mailer 1.20 - SSH Slaves 1.15 Additionally, the following plugins will be removed from distribution: - Pipeline: Classpath Step Please see the

Jenkins plugins security advisory

2017-04-10 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: • Email Extension (Email-ext) 2.57.2 • Environment Injector (EnvInject) 2.0 • Extensible Choice Parameter 1.4.0 • Groovy 2.0 • Job DSL 1.60 • Lockable Resources 2.0 • Warnings 4.61 The following Jenkins

Security advisory pre-announcement

2017-04-19 Thread Daniel Beck
We will publish new Jenkins releases (mainline and 2.46.2 LTS) on Wednesday April 26. These releases will contain fixes for security issues found in current versions of Jenkins, including a critical one. The security advisory will be issued at the same time to provide further information. --

Security advisory pre-announcement

2017-03-13 Thread Daniel Beck
We will provide updates to multiple Jenkins plugins on Monday, March 20. These updates will contain fixes for security issues present in their current releases. This only affects Jenkins plugins, there will be no corresponding security update for Jenkins itself. -- You received this message

Jenkins plugins security advisory

2017-03-07 Thread Daniel Beck
The following plugin updates have been released to fix a security vulnerability: * Maven Pipeline Plugin 0.6 and 2.0-beta-6 Please see the advisory for more details: https://jenkins.io/security/advisory/2017-03-07/ -- You received this message because you are subscribed to the Google Groups

Jenkins plugins security advisory

2017-07-10 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Docker Commons Plugin 1.8 * Git Plugin 3.3.2 and 3.4.0-beta-2 * GitHub Branch Source Plugin 2.0.8 and 2.2.0-beta-2 * Parameterized Trigger Plugin 2.35 * Periodic Backup Plugin 1.5 * Pipeline: Build Step

Jenkins plugins security advisory

2017-04-27 Thread Daniel Beck
The following plugin update has been released to fix a security vulnerability: * Git Client Plugin 2.4.4 Please see the advisory for more details: https://jenkins.io/security/advisory/2017-04-27/ -- You received this message because you are subscribed to the Google Groups "Jenkins

Security advisory pre-announcement

2017-07-31 Thread Daniel Beck
We will provide updates to multiple Jenkins plugins on Monday, August 7. These updates will contain fixes for security issues present in their current releases, including multiple high severity issues. The security advisory will be issued at the same time to provide further information. This

Jenkins plugin security advisory

2017-08-08 Thread Daniel Beck
The following plugin update has been released to fix a security issue: * SAML Plugin 1.0.3 Please see the advisory for more details: https://jenkins.io/security/advisory/2017-08-08/ -- You received this message because you are subscribed to the Google Groups "Jenkins Advisories" group. To

Jenkins plugins security advisory

2017-08-07 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Blue Ocean 1.1.6 * * Config File Provider Plugin 2.16.2 * Datadog Plugin 0.5.7 * Deploy to container Plugin 1.13 * DRY Plugin 2.49 * OWASP Dependency-Check Plugin 2.0.1.2 * Pipeline: Groovy Plugin 2.39 * *

Jenkins vulnerability fixed in 2.57 / 2.46.2 is being exploited

2017-05-15 Thread Daniel Beck
The Jenkins project has received a credible report that the remote code execution vulnerability fixed on April 26[1] is being actively exploited to install and run crypto currency mining tools on machines running Jenkins. According to the report, an executable called `conns` is downloaded and

Re: Security advisory pre-announcement

2017-06-28 Thread Daniel Beck
> On 26. Jun 2017, at 13:50, Daniel Beck <m...@beckweb.net> wrote: > > We will provide updates to multiple Jenkins plugins on Monday, July 3. These > updates will contain fixes for security issues present in their current > releases. > > This o

Re: Critical regression in Jenkins 2.80

2017-09-28 Thread Daniel Beck
> On 27. Sep 2017, at 18:23, Daniel Beck <m...@beckweb.net> wrote: > > We are currently preparing Jenkins 2.81 and strongly recommend new > installations of Jenkins do not use 2.80. 2.81 has been released a few hours ago. More information about this regression in the adv

Critical regression in Jenkins 2.80

2017-09-27 Thread Daniel Beck
We have identified a critical regression in Jenkins 2.80 that results in the setup wizard being disabled for newly set up Jenkins instances. We are tracking this issue as JENKINS-47139. This means that any security options enabled during the setup wizard initialization, most notably

Security advisory pre-announcement

2017-10-04 Thread Daniel Beck
We will publish new Jenkins releases (mainline and 2.73.2 LTS) on Wednesday October 11. These releases will contain fixes for security issues found in current versions of Jenkins. The highest severity is 'high'. The security advisory will be issued at the same time to provide further

Jenkins security advisory

2017-10-11 Thread Daniel Beck
We've released new versions of Jenkins and Swarm Plugin today to fix several security vulnerabilities. These vulnerabilities affect all previous releases: - weekly releases up to and including 2.83 - LTS releases up to and including 2.73.1 - Swarm Plugin (client) up to and including 3.4 We

Security advisory pre-announcement

2017-10-18 Thread Daniel Beck
We will provide updates to multiple Jenkins plugins on Monday, October 23. These updates will contain fixes for security issues present in their current releases. The highest severity is 'medium'. All affected plugins have less than 10,000 reported installations. The security advisory will be

Jenkins plugins security advisory

2017-10-23 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Active Choices (uno-choice) Plugin 2.0 * Build-Publisher Plugin 1.22 * Dependency Graph Viewer Plugin 0.13 * global-build-stats Plugin 1.5 * Multijob Plugin 1.26 Additionally, we announce a vulnerability

Jenkins security advisory

2017-12-05 Thread Daniel Beck
The Jenkins project published a security advisory today: https://jenkins.io/security/advisory/2017-12-05/ This is not the advisory I announced yesterday, that one is still scheduled for tomorrow. -- You received this message because you are subscribed to the Google Groups "Jenkins Advisories"

Jenkins security advisory

2017-12-13 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.95 * Jenkins LTS 2.89.2 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2017-12-14/

Jenkins plugin security advisory

2017-11-16 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Delivery Pipeline Plugin 10.8 Please see the advisory for more information: https://jenkins.io/security/advisory/2017-11-16/ -- You received this message because you are subscribed to the Google Groups

Security advisory pre-announcement

2017-11-02 Thread Daniel Beck
We will publish new Jenkins releases (weekly and 2.73.3 LTS) on Wednesday November 8. These releases will contain fixes for security issues found in current versions of Jenkins. The highest severity is 'low'. The security advisory will be issued at the same time to provide further information.

Jenkins plugin security advisory

2017-12-11 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Script Security Plugin 1.37 Please see the advisory for more information: https://jenkins.io/security/advisory/2017-12-11/ -- You received this message because you are subscribed to the Google Groups

Jenkins plugin security advisory

2017-12-06 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * EC2 Plugin 1.38 Please see the advisory for more information: https://jenkins.io/security/advisory/2017-12-06/ -- You received this message because you are subscribed to the Google Groups "Jenkins

Jenkins security advisory

2018-05-09 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.121 * Jenkins LTS 2.107.3 Additionally, we're announcing security fixes in these previous plugin releases: * Black Duck Hub Plugin 4.0.0 (released 2018-04-25) * Groovy Postbuild 2.4 (released

Security advisory pre-announcement

2018-05-02 Thread Daniel Beck
We will publish new Jenkins releases (weekly and 2.107.3 LTS) on Wednesday May 9. These releases will contain fixes for security issues found in current versions of Jenkins. The highest severity is 'high'. The security advisory will be issued at the same time to provide further information. --

Jenkins plugins security advisory

2018-01-22 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Ant plugin 1.8 * Checkstyle plugin 3.50 * DRY plugin 2.50 * FindBugs plugin 4.72 * Pipeline: Nodes and Processes plugin 2.18 * PMD plugin 3.50 * Release plugin 2.10 * Translation Assistance plugin 1.16 *

Security advisory pre-announcement

2018-01-17 Thread Daniel Beck
We will provide updates to multiple Jenkins plugins on Monday, January 22. These updates will contain fixes for security issues present in their current releases. The highest severity is 'high'. Some affected plugins have more than 100,000 reported installations. The security advisory will be

Jenkins plugins security advisory

2018-02-05 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Android Lint 2.6 * CCM 3.2 * Credentials Binding 1.15 * JUnit 1.24 * Pipeline: Supporting APIs 2.18 Please see the advisory for more information: https://jenkins.io/security/advisory/2018-02-05/ -- You

Jenkins security advisory

2018-02-14 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.107 * Jenkins LTS 2.89.4 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2018-02-14/

Security advisory pre-announcement

2018-02-07 Thread Daniel Beck
We will publish new Jenkins releases (weekly and 2.89.4 LTS) on Wednesday February 14. These releases will contain fixes for security issues found in current versions of Jenkins. The highest severity is 'medium'. The security advisory will be issued at the same time to provide further

Security advisory pre-announcement

2018-02-21 Thread Daniel Beck
We will provide updates to multiple Jenkins plugins on Monday, February 26. These updates will contain fixes for security issues present in their current releases. The highest severity is 'medium'. Some affected plugins have more than 100,000 reported installations. The security advisory will

Jenkins security advisory

2018-08-15 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.138 * Jenkins LTS 2.121.3 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2018-08-15/

Security advisory pre-announcement

2018-08-08 Thread Daniel Beck
We will publish new Jenkins releases (weekly and 2.121.3 LTS) on Wednesday August 15. These releases will contain fixes for security issues found in current versions of Jenkins. The highest severity is 'medium'. The security advisory will be issued at the same time to provide further

Jenkins security advisory

2018-04-11 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.116 * Jenkins LTS 2.107.2 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2018-04-11/

Security advisory pre-announcement

2018-04-12 Thread Daniel Beck
We will provide updates to Jenkins plugins on Monday, April 16. These updates will contain fixes for security issues present in their current releases. The highest severity is 'medium'. The most popular plugin has between 25,000 and 50,000 reported installations. The security advisory will be

Jenkins plugins security advisory

2018-04-16 Thread Daniel Beck
The following Jenkins plugin updates have been released today to fix security vulnerabilities: * Google Login 1.3.1 * HTML Publisher 1.16 Additionally, we're announcing security fixes in these previous plugin releases: * Email Extension 2.62 (released 2018-03-23) * S3 Publisher Plugin 0.11.0

Security advisory pre-announcement

2018-03-21 Thread Daniel Beck
We will publish a security advisory and corresponding updates to multiple Jenkins plugins on Monday, March 26. The most widely installed affected plugin has more than 100,000 reported installations and has a 'medium' severity vulnerability. The highest severity is 'high' and affects a plugin

Security advisory pre-announcement

2018-10-24 Thread Daniel Beck
The Jenkins project will publish updates to multiple Jenkins plugins on Monday, October 29. These updates will contain fixes for security issues present in their current releases. The highest severity is 'high'. The most popular included plugin has more than 100,000 reported installations. The

Jenkins plugins security advisory

2018-10-29 Thread Daniel Beck
The following Jenkins plugin updates have been released today to fix security vulnerabilities: * Pipeline: Groovy 2.60 * Script Security 1.48 Please see the advisory for more information: https://jenkins.io/security/advisory/2018-10-29/ -- You received this message because you are subscribed

Jenkins security advisory

2018-10-10 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.146 * Jenkins LTS 2.138.2 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2018-10-10/

Security advisory pre-announcement

2018-10-04 Thread Daniel Beck
The Jenkins project will publish new Jenkins releases (weekly and 2.138.2 LTS) on Wednesday October 10. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is 'medium'. The security advisory will be issued at the same time to provide

Jenkins plugins security advisory

2018-09-25 Thread Daniel Beck
The following Jenkins plugin updates have been released today to fix security vulnerabilities: * Config File Provider Plugin 3.2 * Crowd 2 Integration Plugin 2.0.1 * Email Extension Template Plugin 1.1 * HipChat Plugin 2.2.1 * JIRA Plugin 3.0.2 * Job Configuration History Plugin 2.18.1 * JUnit

Jenkins security advisory

2019-01-16 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.160 * Jenkins LTS 2.150.2 Please see the advisory for more information: https://jenkins.io/security/advisory/2019-01-16/ -- You received this message because you are subscribed to the Google

Security advisory pre-announcement

2019-01-23 Thread Daniel Beck
The Jenkins project will publish updates to multiple Jenkins plugins on Monday, January 28. These updates will contain fixes for security issues present in their current releases. The highest severity is 'high'. The most popular included plugin has more than 200,000 reported installations. The

Security advisory pre-announcement

2018-11-29 Thread Daniel Beck
The Jenkins project will publish new Jenkins releases (weekly, 2.138.4 LTS, and 2.150.1 LTS) on Wednesday December 5. Jenkins 2.138.4 will only include security fixes as changes since 2.138.3 to allow administrators to apply the security fixes without performing a major update, while 2.150.1 is

Security advisory pre-announcement

2019-01-04 Thread Daniel Beck
The Jenkins project will publish updates to multiple Jenkins plugins on Tuesday, January 8. These updates will contain fixes for security issues present in their current releases. The highest severity is 'high'. The most popular included plugin has more than 200,000 reported installations. The

Jenkins plugins security advisory

2019-01-08 Thread Daniel Beck
The following Jenkins plugin updates have been released today to fix security vulnerabilities: * Pipeline: Declarative Plugin 1.3.4.1 * Pipeline: Groovy Plugin 2.61.1 * Script Security Plugin 1.50 Please see the advisory for more information: https://jenkins.io/security/advisory/2019-01-08/ --

Jenkins plugins security advisory

2019-01-28 Thread Daniel Beck
The following Jenkins plugin updates have been released today to fix security vulnerabilities: * Active Directory Plugin 2.11 * Blue Ocean Plugin 1.10.2 * Config File Provider Plugin 3.5 * Git Plugin 3.9.2 * Groovy Plugin 2.1 * Job Import Plugin 3.1 * Script Security Plugin 1.51 * Token Macro

Security advisory pre-announcement

2019-04-02 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins tomorrow, Wednesday, April 3. The highest severity is 'medium'. The most popular included plugin has between 2,500 and 5,000 reported installations. Several issues will be published without a fix as outlined at

Jenkins plugins security advisory

2019-04-03 Thread Daniel Beck
The following Jenkins plugin updates have recently been released to fix security vulnerabilities: * Netsparker Cloud Scan Plugin 1.1.6 * Youtrack Plugin 0.7.2 We also announce unresolved security issues in the following plugins: * Amazon SNS Build Notifier Plugin * Aqua Security Scanner

Security advisory pre-announcement

2019-03-04 Thread Daniel Beck
The Jenkins project will publish updates to Jenkins plugins on Wednesday, March 6. These updates will contain fixes for security issues present in their current releases. The highest severity is 'high'. The most popular included plugin has more than 200,000 reported installations. The security

Security advisory pre-announcement

2019-03-21 Thread Daniel Beck
The Jenkins project will publish updates to Jenkins plugins on Monday, March 25. These updates will contain fixes for security issues present in their current releases. The highest severity is 'high'. The most popular included plugin has more than 200,000 reported installations. The security

Security advisory pre-announcement

2019-02-15 Thread Daniel Beck
The Jenkins project will publish updates to Jenkins plugins on Tuesday, February 19. These updates will contain fixes for security issues present in their current releases. The highest severity is 'high'. The most popular included plugin has more than 200,000 reported installations. The

Jenkins plugins security advisory

2019-02-19 Thread Daniel Beck
The following Jenkins plugin updates have been released today to fix security vulnerabilities: * Script Security Plugin 1.53 * Cloud Foundry Plugin 2.3.2 We recommend that administrators update Script Security Plugin as soon as possible. Additionally we announce security fixes in these

Security advisory pre-announcement

2019-05-30 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins tomorrow, Friday, May 31. The highest severity is 'high'. The most popular included plugin has between 10,000 and 20,000 reported installations. This affects only Jenkins plugins, there will be no corresponding security

Jenkins plugins security advisory

2019-06-11 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * ElectricFlow Plugin 1.1.7 * JX Resources Plugin 1.0.37 * Token Macro Plugin 2.8 Please see the advisory for more information: https://jenkins.io/security/advisory/2019-06-11/ -- You received this

Jenkins security advisory

2019-04-10 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.172 * Jenkins LTS 2.164.2 Please see the advisory for more information: https://jenkins.io/security/advisory/2019-04-10/ -- You received this message because you are subscribed to the Google

Jenkins plugins security advisory

2019-04-17 Thread Daniel Beck
The following Jenkins plugin updates fix security vulnerabilities: * Azure PublisherSettings Credentials Plugin 1.5 * GitLab Plugin 1.5.12 * jira-ext Plugin 0.9 * ontrack Jenkins Plugin 3.4.1 We also announce unresolved security issues in the following plugins: * XebiaLabs XL Deploy Plugin

Jenkins security advisory

2019-08-28 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.192 * Jenkins LTS 2.176.3 Additionally, the following plugin updates have been released to fix security vulnerabilities: * IBM Application Security on Cloud 1.2.5 * Splunk Plugin 1.8.0 Please

Jenkins plugins security advisory

2019-09-12 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Aqua Security Serverless Scanner Plugin 1.0.5 * Beaker builder Plugin 1.10 * Build Environment Plugin 1.7 * Dashboard View Plugin 2.12 * Git client Plugin 2.8.5 * Script Security Plugin 1.63 Please see

Security advisory pre-announcement

2019-09-18 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly, 2.176.4 LTS and 2.190.1 LTS) on Wednesday, September 25. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is 'medium'. The security advisory will be issued at the

Jenkins plugins security advisory

2019-07-31 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Amazon EC2 Plugin 1.44 * Configuration as Code Plugin 1.25 * Google Kubernetes Engine Plugin 0.6.3 * Maven Integration Plugin 3.4 * Maven Release Plug-in Plugin 0.15.0 * Pipeline: Shared Groovy Libraries

Security advisory pre-announcement

2019-09-30 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins tomorrow, Tuesday, October 1. The highest severity is 'high'. The most popular included plugin has more than 200,000 reported installations. This affects only Jenkins plugins, there will be no corresponding security

Jenkins security advisory

2019-11-21 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Anchore Container Image Scanner Plugin 1.0.20 * Google Compute Engine Plugin 4.2.0 * JIRA Plugin 3.0.11 * QMetry for JIRA - Test Management Plugin 1.13 * Script Security Plugin 1.68 * Spira Importer Plugin

Jenkins plugins security advisory

2019-12-17 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Build Failure Analyzer Plugin 1.24.2 * Gerrit Trigger Plugin 2.30.2 * Maven Release Plugin 0.16.2 * Pipeline Aggregator View Plugin 1.9 * Redgate SQL Change Automation Plugin 2.0.4 * Rundeck Plugin 3.6.6 * Spira

Jenkins plugins security advisory pre-announcement

2019-12-12 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, December 17. The highest severity is 'High'. The most popular included plugin has between 10,000 and 25,000 reported installations. The advisory includes issues that will be published without a fix as outlined

Jenkins security advisory

2019-10-16 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Bumblebee HP ALM Plugin 4.1.4 * Cadence vManager Plugin 2.7.1 * CRX Content Package Deployer Plugin 1.9 * Google Kubernetes Engine Plugin 0.7.1 * Google OAuth Credentials Plugin 0.10 * iceScrum Plugin

Jenkins security advisory

2019-10-23 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Bitbucket OAuth Plugin 0.10 * Dynatrace Application Monitoring Plugin 2.1.4 * Mattermost Notification Plugin 2.7.1 * Zulip Plugin 1.1.1 Additionally, we announce unresolved security issues in the

Security advisory pre-announcement

2019-11-19 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Thursday, November 21. The highest severity is 'high'. The most popular included plugin has more than 200,000 reported installations. This affects only Jenkins plugins, there will be no corresponding security update

Jenkins security advisory

2019-09-25 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.197 * Jenkins LTS 2.176.4 and 2.190.1 The following Jenkins plugin updates have been released to fix security vulnerabilities: * Aqua MicroScanner Plugin 1.0.8 * Aqua Security Scanner Plugin

Security advisory pre-announcement

2019-10-14 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, October 16. The highest severity is 'high' and affects a plugin with less than 1000 installations. The most popular included plugin has between 5,000 and 10,000 reported installations and has a 'medium'

Jenkins security advisory

2020-01-29 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.219 * Jenkins LTS 2.204.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Code Coverage API Plugin 1.1.3 * Fortify Plugin 19.2.30 Additionally, we announce unresolved

Jenkins plugins security advisory pre-announcement

2020-02-07 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, February 12. The highest severity is 'High'. The most popular included plugin has more than 200,000 reported installations. The advisory includes issues that will be published without a fix as outlined at

Jenkins security advisory pre-announcement

2020-01-23 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.204.2) on Wednesday, January 29. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

Jenkins plugins security advisory

2020-01-15 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Amazon EC2 Plugin 1.48 * Health Advisor by CloudBees Plugin 3.0.1 * Redgate SQL Change Automation Plugin 2.0.5 * Robot Framework Plugin 2.0.1 Additionally, we announce unresolved security issues in the following

Jenkins plugins security advisory pre-announcement

2020-04-15 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Thursday, April 16. The highest severity is 'High'. The most popular included plugin is installed on less than 1% of known instances. This affects only Jenkins plugins, there will be no corresponding security update

Jenkins plugins security advisory

2020-04-16 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * AWS SAM Plugin 1.2.3 * Copr Plugin 0.6.1 * Parasoft Findings Plugin 10.4.4 * Yaml Axis Plugin 0.2.1 Please see the advisory for more information: https://jenkins.io/security/advisory/2020-04-16/ -- You received

Jenkins plugins security advisory

2020-04-07 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * AWSEB Deployment Plugin 0.3.20 * Code Coverage API Plugin 1.1.5 * FitNesse Plugin 1.33 * Gatling Plugin 1.3.0 * useMango Runner Plugin 1.5 Please see the advisory for more information:

Jenkins plugins security advisory pre-announcement

2020-04-03 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, April 7. The highest severity is 'High'. The most popular included plugin is installed on between 3% and 10% of known instances. The advisory may include issues that will be published without a fix as outlined

Jenkins security advisory

2020-03-25 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.228 * Jenkins LTS 2.204.6 and 2.222.1 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Artifactory Plugin 3.6.0 and 3.6.1 * Azure Container Service Plugin 1.0.2 * OpenShift

Jenkins plugins security advisory pre-announcement

2020-05-04 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, May 6. The highest severity is 'High' and affects plugins installed on less than 1% of known instances. The most popular included plugins are installed on more than 75% of known instances and have 'Medium'

Jenkins security advisory pre-announcement

2020-03-19 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly, LTS 2.204.6, and LTS 2.222.1) on Wednesday, March 25. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same

Jenkins plugins security advisory pre-announcement

2020-09-14 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, September 16. The highest severity is 'High' and affects plugins installed on between 3% and 10% of known instances. The most popular included plugins are installed on more than 75% of known instances and

Jenkins plugins security advisory

2020-09-01 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Build Failure Analyzer Plugin 1.27.1 * Cadence vManager Plugin 3.0.5 * database Plugin 1.7 * Git Parameter Plugin 0.9.13 * Parameterized Remote Trigger Plugin 3.1.4 * SoapUI Pro Functional Testing Plugin 1.4

Jenkins plugins security advisory

2020-10-08 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Active Choices Plugin 2.5 * Audit Trail Plugin 3.7 * couchdb-statistics Plugin 0.4 * Role-based Authorization Strategy Plugin 3.1 Additionally, we announce unresolved security issues in the following plugins: *

Jenkins plugins security advisory pre-announcement

2020-10-06 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Thursday, October 8. The highest severity is 'High'. The most popular included plugin is installed on between 25% and 75% of known instances. The advisory includes issues that will be published without a fix as outlined

Jenkins plugins security advisory pre-announcement

2020-08-28 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Tuesday, September 1. The highest severity is 'High'. The most popular included plugin is installed on between 10% and 25% of known instances. The advisory includes issues that will be published without a fix as

Jenkins security advisory

2020-08-17 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.243 (originally released 2020-06-30) * Jenkins LTS 2.235.5 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2020-08-17/? -- You received this message because you are

Jenkins plugins security advisory

2020-09-23 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Implied Labels Plugin 0.7 * Liquibase Runner Plugin 1.4.8 * Lockable Resources Plugin 2.9 * Script Security Plugin 1.75 * Warnings Plugin 5.0.2 Please see the advisory for more information:

Jenkins plugins security advisory pre-announcement

2020-05-29 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, June 3. The highest severity is 'High' and affects plugins installed on between 1% and 3% of known instances. The most popular included plugins are installed on more than 75% of known instances and have

Jenkins plugins security advisory

2020-09-16 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Blue Ocean Plugin 1.23.3 * computer-queue-plugin Plugin 1.6 * Email Extension Plugin 2.76 * Health Advisor by CloudBees Plugin 3.2.1 * Mailer Plugin 1.32.1 * Perfecto Plugin 1.18 * Pipeline Maven Integration Plugin

Jenkins plugins security advisory pre-announcement

2020-09-18 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, September 23. The highest severity is 'High'. The most popular included plugin is installed on more than 75% of known instances. This affects only Jenkins plugins, there will be no corresponding security

Jenkins security advisory

2020-08-12 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.252 * Jenkins LTS 2.235.4 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Email Extension Plugin 2.74 * Pipeline Maven Integration Plugin 3.8.3 * Yet Another Build Visualizer

Jenkins security advisory pre-announcement

2020-08-06 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.235.4) on Wednesday, August 12. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

Jenkins plugins security advisory pre-announcement

2020-07-01 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins on Thursday, July 2. The highest severity is 'High' and affects plugins installed on less than 1% of known instances. The most popular included plugins are installed on between 1% and 3% of known instances and have

Jenkins plugins security advisory

2020-06-03 Thread Daniel Beck
The following Jenkins plugin updates contain fixes for security vulnerabilities: * Compact Columns Plugin 1.12 * ECharts API Plugin 4.7.0-4 * Script Security Plugin 1.73 * Self-Organizing Swarm Plug-in Modules Plugin 3.21 Additionally, we announce unresolved security issues in the following

Jenkins security advisory pre-announcement

2020-08-14 Thread Daniel Beck
The Jenkins project plans to publish a new Jenkins LTS release (2.235.5) next week (week of August 17). This update will contain a fix for a security issue present in the current version of Jenkins LTS. The severity is "Critical". The security advisory will be issued at the same time to provide

Jenkins security advisory pre-announcement

2021-01-07 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.263.2) on Wednesday, January 13. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

  1   2   >