oss-sec mailing list archives

CVE request: Jenkins


From: Moritz Muehlenhoff <jmm () debian org>
Date: Thu, 27 Dec 2012 21:31:51 +0100

Hi,
these Jenkins security issues don't seem to have CVEs assigned so far:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2012-11-20 

I can't provide links to upstream fixes, but three CVE IDs seem 
needed (HTTP response splitting, open redirect and XSS)

Cheers,
        Moritz


Current thread: