Vulnerability List: SECURITY-506 / CVE-2018-1000067 (medium) - Improperly secured form validation for proxy configuration allowed Server-Side Request Forgery SECURITY-705 / CVE-2018-6356 (medium) - Path traversal vulnerability allows access to files outside plugin resources SECURITY-717 / CVE-2018-1000068 (medium) - Improper input validation allows unintended access to plugin resource files on case-insensitive file systems Affected Versions: Jenkins weekly up to and including 2.106 Jenkins LTS up to and including 2.89.3 Fix: Jenkins weekly should be updated to version 2.107 Jenkins LTS should be updated to version 2.89.4 Credit: Daniel Beck, CloudBees, Inc. for SECURITY-506, SECURITY-717 * Kapil Kulkarni for SECURITY-705