From 3830bfc71d58eceb49ce886c15e2e443deaeac6b Mon Sep 17 00:00:00 2001 From: Franco Fichtner Date: Wed, 5 Dec 2018 19:50:02 +0100 Subject: [PATCH] security/vuxml: sync with upstream Taken from: HardenedBSD --- security/vuxml/vuln.xml | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index b3e73cc92f6..4ff1b265d7f 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,43 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + jenkins -- multiple vulnerabilities + + + jenkins + 2.154 + + + jenkins-lts + 2.138.3 + + + + +

Jenkins Security Advisory:

+
+

Description

+
(Critical) SECURITY-595
+

Code execution through crafted URLs

+
(Medium) SECURITY-904
+

Forced migration of user records

+
(Medium) SECURITY-1072
+

Workspace browser allowed accessing files outside the workspace

+
(Medium) SECURITY-1193
+

Potential denial of service through cron expression form validation

+
+ +
+ + https://jenkins.io/security/advisory/2018-12-05/ + + + 2018-12-05 + 2018-12-05 + +
+ moodle -- Login CSRF vulnerability