-
Notifications
You must be signed in to change notification settings - Fork 594
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency org.jenkins-ci.plugins:sidebar-link to v2 [security] #5027
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/maven-org.jenkins-ci.plugins-sidebar-link-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
fix(deps): update dependency org.jenkins-ci.plugins:sidebar-link to v2 [security] #5027
renovate
wants to merge
1
commit into
master
from
renovate/maven-org.jenkins-ci.plugins-sidebar-link-vulnerability
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
827e0ff
to
985fc00
Compare
2581d4b
to
a43d634
Compare
1f60809
to
3bacc6b
Compare
d0f41b3
to
fdb4ee7
Compare
00a74a9
to
baefc0b
Compare
dc8c663
to
123db08
Compare
9a1a875
to
aee9012
Compare
38a0706
to
ad9d66a
Compare
ad9d66a
to
683af70
Compare
/it-go |
683af70
to
9b133a8
Compare
/it-go |
9b133a8
to
cf1cc09
Compare
/it-go |
cf1cc09
to
b5e98d4
Compare
/it-go |
b5e98d4
to
b6de425
Compare
/it-go |
b6de425
to
cb83cfe
Compare
/it-go |
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.9.1
->2.2.2
GitHub Vulnerability Alerts
CVE-2023-32985
Jenkins Sidebar Link Plugin allows specifying files in the
userContent/
directory for use as link icons.Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validation.
This allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Sidebar Link Plugin 2.2.2 ensures that only files located within the expected
userContent/
directory can be accessed.Release Notes
jenkinsci/sidebar-link-plugin (org.jenkins-ci.plugins:sidebar-link)
v2.2.1
v2.2.0
v2.1.0
(PR #36,
fixes #28,
fixes JENKINS-55710)
v2.0.2
(PR #38,
fixes #37)
v2.0.1
(PR #33)
(PR #34)
v2.0.0
hudson.plugins.sidebar_link.SidebarLinkPlugin.xml
file on the Jenkinscontroller. Previous versions used
sidebar-link.xml
instead.(PR #29)
(PR #30)
(PR #32)
(PR #25,
fixes JENKINS-63149)
v1.12.1
(PR #27,
mostly fixes #21)
v1.12.0
(PR #15)
(PR #16)
(PR #18)
(PR #19)
(PR #20)
(PR #24)
v1.11.0
(PR #12)
(PR #13)
(PR #14)
v1.10
types
(PR #9,
fixes JENKINS-33458)
(PR #10)
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.