Skip to content

トピトピニュース

Header Image
Archive

Month: March 2022

35 Posts

Featured

Posted byUbergizmo Japan
iPhone SE 5Gが不人気で生産を大幅カット?
Posted byUbergizmo Japan
SteelSeriesからAndroid/Chrome OS搭載デバイス向けの新型ゲームコントローラーが登場
Posted byGitHub
[org.jenkins-ci.plugins:proxmox] SSL/TLS certificate validation globally disabled by Jenkins Proxmox Plugin
Posted byGitHub
[org.jenkins-ci.plugins:ci-with-toad-edge] Arbitrary file read vulnerability in Jenkins Continuous Integration with Toad Edge Plugin

[org.jenkins-ci.plugins:list-git-branches-parameter] Stored Cross-site Scripting vulnerability in Jenkins List Git Branches Parameter Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 03/16/202212/01/2022

Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the ‘List Git branches (and more)’ parameter, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permissio…

[org.jenkins-ci.plugins:release-helper] CSRF vulnerability in Jenkins Release Helper Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/16/202212/01/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-27…

[org.jenkins-ci.plugins:dbCharts] Passwords stored in plain text by Jenkins dbCharts Plugin

  • Posted inLOW
  • Posted byGitHub
  • 03/16/202212/01/2022

Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file hudson.plugins.dbcharts.DbChartPublisher.xml on the Jenkins controller as part of its configuration.
These passwords can be viewed b…

[io.jenkins.plugins:environment-dashboard] Stored Cross-site Scripting vulnerability in Jenkins Environment Dashboard Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 03/16/202212/01/2022

Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/C…

[com.incapptic.plugins:incapptic-connect-uploader] Personal tokens stored in plain text by Jenkins incapptic connect uploader Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/16/202212/01/2022

Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Ref…

[org.jenkins-ci.plugins:release-helper] Missing permission checks in Jenkins Release Helper Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/16/202212/01/2022

A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
References

https://nvd.nist.gov/vuln/detail/CVE-2…

PS5と相性抜群!次世代対応の密閉型ゲーミングヘッドセット「Arctis 7P+ Wireless」をレビュー!

  • Posted inUncategorized
  • Posted byFunglr Games(日本語)
  • 03/13/2022

ゲームをプレイする時、使用しているPCはもちろんですが、オーディオ面も重要になってきますよね。ゲーム…

[org.postgresql:postgresql] Path traversal in org.postgresql:postgresql

  • Posted inLOW
  • Posted byGitHub
  • 03/11/202209/08/2022

** DISPUTED ** In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that …

最大40Gbpsの超高速データ転送実現するゲーミングケーブル「Razer Thunderbolt 4 ケーブル」登場!

  • Posted inUncategorized
  • Posted byFunglr Games(日本語)
  • 03/09/2022

理想のゲーミング環境を構築するのに、一定以上の性能を持つゲーミングデバイスは必要になってきますよね。…

Googleがサイバーセキュリティ企業のMandiantを買収へ

  • Posted inUncategorized
  • Posted byねっと特報
  • 03/08/2022

Googleがサイバーセキュリティ企業のMandiantを買収する意向であることを発表した。Mand…

Posts navigation

Previous Posts 1 2 3 4 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close