Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2025-01-22

2025-01-22 Jan 22, 2025 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2025-01-22/. 6 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2025-01-22/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

7 lines
Showing 1–7 of 7
CVE-2025-24399 BR2025-0000-009478 SECURITY-3461 unclaimed
Improper handling of case sensitivity in OpenId Connect Authentication Plugin
Credited as James Nord, CloudBees, Inc.
CVE-2025-24402 BR2025-0000-009479 SECURITY-3094 unclaimed
CSRF vulnerability and missing permission checks in Azure Service Fabric Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2025-24397 BR2025-0000-009480 SECURITY-3260 unclaimed
Incorrect permission check in GitLab Plugin allows enumerating credentials IDs
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2025-24397 BR2025-0000-009481 SECURITY-3260 unclaimed
Incorrect permission check in GitLab Plugin allows enumerating credentials IDs
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2025-24400 BR2025-0000-009482 SECURITY-3485 unclaimed
Cache confusion in Eiffel Broadcaster Plugin
Credited as Magnus Bäck, Axis Communications
CVE-2025-24398 BR2025-0000-009483 SECURITY-3434 unclaimed
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
Credited as Vincent Latombe, CloudBees, Inc.
CVE-2025-24401 BR2025-0000-009484 SECURITY-3062 unclaimed
Disabled permissions can be granted by Folder-based Authorization Strategy Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.