Jenkins security advisory

2024-03-20 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.444 * Jenkins LTS 2.440.2 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2024-03-20/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory

2024-01-24 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.442 * Jenkins LTS 2.426.3 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Git server Plugin 99.101.v720e86326c09 * GitLab Branch Source Plugin 688.v5fa_356ee8520 * Matrix

Jenkins security advisory pre-announcement

2024-01-17 Thread 'Kevin Guerroudj' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.426.3) on Wednesday, January 24. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Critical". The security advisory will be issued at the same time to

Jenkins security advisory

2023-10-18 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.428 * Jenkins LTS 2.414.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2023-10-18/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory

2023-09-20 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.424 * Jenkins LTS 2.414.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Build Failure Analyzer Plugin 2.4.2 Please see the advisory for more information:

Jenkins security advisory pre-announcement

2023-09-14 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.414.2) on Wednesday, September 20. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

Jenkins security advisory

2023-07-26 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.416 * Jenkins LTS 2.401.3 The following Jenkins plugin updates contain fixes for security vulnerabilities: * GitLab Authentication Plugin 1.18 * Gradle Plugin 2.8.1 * Qualys Web App Scanning Connector Plugin

Jenkins security advisory pre-announcement

2023-07-20 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.401.3) on Wednesday, July 26. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to provide

Jenkins security advisory

2023-06-14 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.400 (released 2023-04-11) * Jenkins LTS 2.401.1 (released 2023-05-31) The following Jenkins plugin updates contain fixes for security vulnerabilities: * Checkmarx Plugin 2023.2.6 * Dimensions Plugin 0.9.3.1 *

Jenkins security advisory pre-announcement

2023-06-13 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project will publish a security advisory for Jenkins and Jenkins plugins on Wednesday, June 14. It announces a security vulnerability that is already fixed in the latest weekly releases and Jenkins LTS 2.401.1. Its severity is 'High'. Additionally, it announces security issues in

Jenkins security advisory

2023-03-08 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.394 * Jenkins LTS 2.375.4 and 2.387.1 The following Jenkins component updates contain fixes for security vulnerabilities: * update-center2 3.15 Please see the advisory for more information:

Jenkins security advisory pre-announcement

2023-03-03 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly, LTS 2.375.4, and LTS 2.387.1) on Wednesday, March 8. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same

Jenkins security advisory

2023-02-09 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins deliverables contain fixes for security vulnerabilities: * Jenkins controller and agent Docker images Please see the advisory for more information: https://www.jenkins.io/security/advisory/2023-02-09/ -- You received this message because you are subscribed to the Google

Jenkins security advisory

2022-09-21 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.370 [see footnote 1] The following Jenkins plugin updates contain fixes for security vulnerabilities: * Anchore Container Image Scanner Plugin 1.0.25 * Compuware Common Configuration Plugin 1.0.15 * NS-ND

Jenkins security advisory

2022-09-09 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.263 * Jenkins LTS 2.361.1 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2022-09-09/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory

2022-06-22 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.356 * Jenkins LTS 2.332.4 and 2.346.1 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Embeddable Build Status Plugin 2.0.4 * Hidden Parameter Plugin 0.0.5 * JUnit Plugin

Jenkins security advisory pre-announcement

2022-06-15 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly, LTS 2.332.4, and LTS 2.346.1) on Wednesday, June 22. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same

Jenkins security advisory

2022-02-09 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.334 * Jenkins LTS 2.319.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2022-02-09/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory pre-announcement

2022-02-07 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.319.3) on Wednesday, February 9. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to

Jenkins security advisory

2022-01-12 Thread 'Wadeck Follonier' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.330 * Jenkins LTS 2.319.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Active Directory Plugin 2.25.1 * Badge Plugin 1.9.1 * Bitbucket Branch Source Plugin

Jenkins security advisory pre-announcement

2022-01-05 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.319.2) on Wednesday, January 12. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to

Jenkins security advisory

2021-11-04 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.319 * Jenkins LTS 2.303.3 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Subversion Plugin 2.15.1 Please see the advisory for more information:

Jenkins security advisory pre-announcement

2021-11-01 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.303.3) on Thursday, November 4. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Critical". The security advisory will be issued at the same time to

Jenkins security advisory

2021-10-06 Thread 'Wadeck Follonier' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.315 * Jenkins LTS 2.303.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Git Plugin 4.8.3 Please see the advisory for more information:

Jenkins security advisory pre-announcement

2021-10-04 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.303.2) on Wednesday, October 6. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to

Jenkins security advisory

2021-06-30 Thread 'Daniel Beck' via Jenkins Advisories
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.300 * Jenkins LTS 2.289.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * CAS Plugin 1.6.1 * requests-plugin 2.2.7, 2.2.8, and 2.2.13 * Selenium HTML report Plugin 1.1

Jenkins security advisory pre-announcement

2021-06-23 Thread 'Daniel Beck' via Jenkins Advisories
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.289.2) on Wednesday, June 30. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to provide

Jenkins security advisory

2021-04-20 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.286 * Jenkins LTS 2.277.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-04-20/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory

2021-04-07 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.287 * Jenkins LTS 2.277.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Micro Focus Application Automation Tools Plugin 6.8 * promoted builds Plugin 3.9.1 Please see the

Jenkins security advisory pre-announcement

2021-03-31 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.277.2) on Wednesday, April 7. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "Medium". The security advisory will be issued at the same time to

Jenkins security advisory

2021-02-19 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.280 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-02-19/ -- You received this message because you are subscribed to the Google Groups "Jenkins Advisories" group.

Jenkins security advisory

2021-01-26 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.276 * Jenkins LTS 2.263.3 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2021-01-26/ -- You received this message because you are subscribed to the Google Groups

Jenkins security advisory

2021-01-13 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.275 * Jenkins LTS 2.263.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Bumblebee HP ALM Plugin 4.1.6 * TICS Plugin 2020.3.0.7 * TraceTronic ECU-TEST Plugin 2.24 Please

Jenkins security advisory pre-announcement

2021-01-07 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.263.2) on Wednesday, January 13. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

Jenkins security advisory

2020-12-03 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Chaos Monkey Plugin 0.4 and 0.4.1 * CVS Plugin 2.17 * Plugin Installation Manager Tool 2.2.0 * Shelve Project Plugin 3.1 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2020-12-03/?

Jenkins security advisory pre-announcement

2020-12-02 Thread Daniel Beck
The Jenkins project will publish a security advisory for Jenkins plugins and other components on Thursday, December 3. The highest severity is 'High'. The most popular included plugin is installed on between 10% and 25% of known instances. -- You received this message because you are

Jenkins security advisory

2020-08-17 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.243 (originally released 2020-06-30) * Jenkins LTS 2.235.5 Please see the advisory for more information: https://www.jenkins.io/security/advisory/2020-08-17/? -- You received this message because you are

Jenkins security advisory pre-announcement

2020-08-14 Thread Daniel Beck
The Jenkins project plans to publish a new Jenkins LTS release (2.235.5) next week (week of August 17). This update will contain a fix for a security issue present in the current version of Jenkins LTS. The severity is "Critical". The security advisory will be issued at the same time to provide

Jenkins security advisory

2020-08-12 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.252 * Jenkins LTS 2.235.4 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Email Extension Plugin 2.74 * Pipeline Maven Integration Plugin 3.8.3 * Yet Another Build Visualizer

Jenkins security advisory pre-announcement

2020-08-06 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.235.4) on Wednesday, August 12. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

Jenkins security advisory

2020-07-15 Thread Wadeck Follonier
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.245 * Jenkins LTS 2.235.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Deployer Framework Plugin 1.3 * Gitlab Authentication Plugin 1.6 * Matrix Authorization Strategy

Jenkins security advisory pre-announcement

2020-07-08 Thread Wadeck Follonier
The Jenkins project plans to publish new Jenkins releases (2.245, LTS 2.235.2) on Wednesday, July 15. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to provide

Jenkins security advisory

2020-03-25 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.228 * Jenkins LTS 2.204.6 and 2.222.1 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Artifactory Plugin 3.6.0 and 3.6.1 * Azure Container Service Plugin 1.0.2 * OpenShift

Jenkins security advisory pre-announcement

2020-03-19 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly, LTS 2.204.6, and LTS 2.222.1) on Wednesday, March 25. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same

Jenkins security advisory

2020-01-29 Thread Daniel Beck
The following Jenkins updates contain fixes for security vulnerabilities: * Jenkins 2.219 * Jenkins LTS 2.204.2 The following Jenkins plugin updates contain fixes for security vulnerabilities: * Code Coverage API Plugin 1.1.3 * Fortify Plugin 19.2.30 Additionally, we announce unresolved

Jenkins security advisory pre-announcement

2020-01-23 Thread Daniel Beck
The Jenkins project plans to publish new Jenkins releases (weekly and LTS 2.204.2) on Wednesday, January 29. These updates will contain fixes for security issues present in current versions of Jenkins. The highest severity is "High". The security advisory will be issued at the same time to

Jenkins security advisory

2019-11-21 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Anchore Container Image Scanner Plugin 1.0.20 * Google Compute Engine Plugin 4.2.0 * JIRA Plugin 3.0.11 * QMetry for JIRA - Test Management Plugin 1.13 * Script Security Plugin 1.68 * Spira Importer Plugin

Jenkins security advisory

2019-10-23 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Bitbucket OAuth Plugin 0.10 * Dynatrace Application Monitoring Plugin 2.1.4 * Mattermost Notification Plugin 2.7.1 * Zulip Plugin 1.1.1 Additionally, we announce unresolved security issues in the

Jenkins security advisory

2019-10-16 Thread Daniel Beck
The following Jenkins plugin updates have been released to fix security vulnerabilities: * Bumblebee HP ALM Plugin 4.1.4 * Cadence vManager Plugin 2.7.1 * CRX Content Package Deployer Plugin 1.9 * Google Kubernetes Engine Plugin 0.7.1 * Google OAuth Credentials Plugin 0.10 * iceScrum Plugin

Jenkins security advisory

2019-09-25 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.197 * Jenkins LTS 2.176.4 and 2.190.1 The following Jenkins plugin updates have been released to fix security vulnerabilities: * Aqua MicroScanner Plugin 1.0.8 * Aqua Security Scanner Plugin

Jenkins security advisory

2019-08-28 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.192 * Jenkins LTS 2.176.3 Additionally, the following plugin updates have been released to fix security vulnerabilities: * IBM Application Security on Cloud 1.2.5 * Splunk Plugin 1.8.0 Please

Jenkins security advisory

2019-04-10 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.172 * Jenkins LTS 2.164.2 Please see the advisory for more information: https://jenkins.io/security/advisory/2019-04-10/ -- You received this message because you are subscribed to the Google

Jenkins security advisory

2019-01-16 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.160 * Jenkins LTS 2.150.2 Please see the advisory for more information: https://jenkins.io/security/advisory/2019-01-16/ -- You received this message because you are subscribed to the Google

Jenkins security advisory

2018-10-10 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.146 * Jenkins LTS 2.138.2 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2018-10-10/

Jenkins security advisory

2018-08-15 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.138 * Jenkins LTS 2.121.3 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2018-08-15/

Jenkins security advisory

2018-05-09 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.121 * Jenkins LTS 2.107.3 Additionally, we're announcing security fixes in these previous plugin releases: * Black Duck Hub Plugin 4.0.0 (released 2018-04-25) * Groovy Postbuild 2.4 (released

Jenkins security advisory

2018-04-11 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.116 * Jenkins LTS 2.107.2 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2018-04-11/

Jenkins security advisory

2018-02-14 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.107 * Jenkins LTS 2.89.4 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2018-02-14/

Jenkins security advisory

2017-12-13 Thread Daniel Beck
The following Jenkins updates have been released to fix security vulnerabilities: * Jenkins weekly 2.95 * Jenkins LTS 2.89.2 Please see the advisory and announcement blog post for more information: https://jenkins.io/security/advisory/2017-12-14/

Jenkins security advisory

2017-12-05 Thread Daniel Beck
The Jenkins project published a security advisory today: https://jenkins.io/security/advisory/2017-12-05/ This is not the advisory I announced yesterday, that one is still scheduled for tomorrow. -- You received this message because you are subscribed to the Google Groups "Jenkins Advisories"

Jenkins security advisory

2017-10-11 Thread Daniel Beck
We've released new versions of Jenkins and Swarm Plugin today to fix several security vulnerabilities. These vulnerabilities affect all previous releases: - weekly releases up to and including 2.83 - LTS releases up to and including 2.73.1 - Swarm Plugin (client) up to and including 3.4 We