Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency org.jenkins-ci.plugins.workflow:workflow-job to v1295 [SECURITY] #97

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 25, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.jenkins-ci.plugins.workflow:workflow-job 2.42 -> 1295.v395eb_7400005 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2023-32977

Jenkins Pipeline: Job Plugin 1292.v27d8cc3e2602 and earlier does not escape the display name of the build that caused an earlier build to be aborted, when "Do not allow concurrent builds" is set.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.

The Jenkins security team is not aware of any plugins that allow the exploitation of this vulnerability, as the build name must be set before the build starts.
Pipeline: Job Plugin 1295.v395eb_7400005 escapes the display name of the build that caused an earlier build to be aborted.


Release Notes

jenkinsci/workflow-job-plugin (org.jenkins-ci.plugins.workflow:workflow-job)

v1295.v395eb_7400005

Compare Source

v1292.v27d8cc3e2602

Compare Source

👷 Changes for plugin developers

📦 Dependency updates

v1289.1291.vb_7c188e7e7df

Compare Source

v1289.vd1c337fd5354

Compare Source

👷 Changes for plugin developers

📦 Dependency updates

v1284.v2fe8ed4573d4

Compare Source

👷 Changes for plugin developers

v1282.ve6d865025906

Compare Source

🐛 Bug fixes

👻 Maintenance

📦 Dependency updates

v1268.v6eb_e2ee1a_85a

Compare Source

👷 Changes for plugin developers

📦 Dependency updates

v1254.v3f64639b_11dd

Compare Source

👷 Changes for plugin developers

📦 Dependency updates

v1249.v7d974144cc14

Compare Source

🐛 Bug fixes

v1246.v6110f5347f1f

Compare Source

🐛 Bug fixes

  • WorkflowRun.doTerm and doKill need to redirect back to the build (#​303) @​jglick

👻 Maintenance

📦 Dependency updates

v1239.v71b_b_a_124a_725

Compare Source

🚀 New features and improvements

v1236.vc3a_d1602f439

Compare Source

🚀 New features and improvements

📦 Dependency updates

v1232.v5a_4c994312f1

Compare Source

🚀 New features and improvements

📦 Dependency updates

v1229.vb_7c2419a_b_558

Compare Source

🐛 Bug fixes

v1226.v44f718dcfe1f

Compare Source

🚀 New features and improvements

v1207.1209.v69351208a_5a_7

Compare Source

v1207.ve6191ff089f8

Compare Source

👷 Changes for plugin developers

v1206.vc48d96b_930b_2

Compare Source

🚀 New features and improvements

📦 Dependency updates

v1203.v7b_7023424efe

Compare Source

🚀 New features and improvements

👻 Maintenance

v1189.va_d37a_e9e4eda_

Compare Source

👷 Changes for plugin developers

📦 Dependency updates

v1186.v8def1a_5f3944

Compare Source

🐛 Bug fixes

v1182.v60a_e6279b_579

Compare Source

🚀 New features and improvements

v1181.va_25d15548158

Compare Source

🐛 Bug fixes

v1180.v04c4e75dce43

Compare Source

👷 Changes for plugin developers

📦 Dependency updates

v1174.1176.va_29023983d67

Compare Source

v1174.vdcb_d054cf74a_

Compare Source

🚀 New features and improvements

📝 Documentation updates

v1167.v8fe861b_09ef9

Compare Source

🚀 New features and improvements

🐛 Bug fixes

📦 Dependency updates

🚦 Tests

  • Skip tests using @ASTTest which fail when LibraryDecorator is present (#​208) @​jglick

v1156.v7539182e7b_d5

Compare Source

🚀 New features and improvements

📦 Dependency updates

👻 Maintenance

v1145.v7f2433caa07f

🚀 New features and improvements

👻 Maintenance

🚦 Tests


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title Update dependency org.jenkins-ci.plugins.workflow:workflow-job to v1295 [SECURITY] Update dependency org.jenkins-ci.plugins.workflow:workflow-job to v1295 [SECURITY] - autoclosed Sep 25, 2024
@renovate renovate bot closed this Sep 25, 2024
@renovate renovate bot deleted the renovate/maven-org.jenkins-ci.plugins.workflow-workflow-job-vulnerability branch September 25, 2024 16:50
@renovate renovate bot changed the title Update dependency org.jenkins-ci.plugins.workflow:workflow-job to v1295 [SECURITY] - autoclosed Update dependency org.jenkins-ci.plugins.workflow:workflow-job to v1295 [SECURITY] Sep 26, 2024
@renovate renovate bot restored the renovate/maven-org.jenkins-ci.plugins.workflow-workflow-job-vulnerability branch September 26, 2024 20:25
@renovate renovate bot reopened this Sep 26, 2024
@renovate renovate bot force-pushed the renovate/maven-org.jenkins-ci.plugins.workflow-workflow-job-vulnerability branch from 082c836 to 27e15c3 Compare September 26, 2024 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants