Date: Wed, 22 Jun 2022 19:11:51 GMT From: Li-Wen Hsu <lwhsu@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: 28676937f7e1 - main - security/vuxml: Document Jenkins Security Advisory 2022-06-22 Message-ID: <202206221911.25MJBpc8036885@gitrepo.freebsd.org>
next in thread | raw e-mail | index | archive | help
The branch main has been updated by lwhsu: URL: https://cgit.FreeBSD.org/ports/commit/?id=28676937f7e12203df395188b61af15f451fa006 commit 28676937f7e12203df395188b61af15f451fa006 Author: Li-Wen Hsu <lwhsu@FreeBSD.org> AuthorDate: 2022-06-22 19:05:48 +0000 Commit: Li-Wen Hsu <lwhsu@FreeBSD.org> CommitDate: 2022-06-22 19:11:40 +0000 security/vuxml: Document Jenkins Security Advisory 2022-06-22 Sponsored by: The FreeBSD Foundation --- security/vuxml/vuln-2022.xml | 41 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) diff --git a/security/vuxml/vuln-2022.xml b/security/vuxml/vuln-2022.xml index eb6d8c7f454d..d6f194bed4da 100644 --- a/security/vuxml/vuln-2022.xml +++ b/security/vuxml/vuln-2022.xml @@ -1,3 +1,44 @@ + <vuln vid="25be46f0-f25d-11ec-b62a-00e081b7aa2d"> + <topic>jenkins -- multiple vulnerabilities</topic> + <affects> + <package> + <name>jenkins</name> + <range><lt>2.356</lt></range> + </package> + <package> + <name>jenkins-lts</name> + <range><lt>2.346.1</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Jenkins Security Advisory:</p> + <blockquote cite="https://www.jenkins.io/security/advisory/2022-06-22/"> + <h1>Description</h1> + <h5>(High) SECURITY-2781 / CVE-2022-34170 (SECURITY-2779), CVE-2022-34171 (SECURITY-2761), CVE-2022-34172 (SECURITY-2776), CVE-2022-34173 (SECURITY-2780)</h5> + <p>Multiple XSS vulnerabilities</p> + <h5>(Medium) SECURITY-2566 / CVE-2022-34174</h5> + <p>Observable timing discrepancy allows determining username validity</p> + <h5>(Medium) Unauthorized view fragment access</h5> + <p>SECURITY-2777 / CVE-2022-34175</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2022-34170</cvename> + <cvename>CVE-2022-34171</cvename> + <cvename>CVE-2022-34172</cvename> + <cvename>CVE-2022-34173</cvename> + <cvename>CVE-2022-34174</cvename> + <cvename>CVE-2022-34175</cvename> + <url>https://www.jenkins.io/security/advisory/2022-06-22/</url> + </references> + <dates> + <discovery>2022-06-22</discovery> + <entry>2022-06-22</entry> + </dates> + </vuln> + <vuln vid="4eeb93bf-f204-11ec-8fbd-d4c9ef517024"> <topic>OpenSSL -- Command injection vulnerability</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202206221911.25MJBpc8036885>