Skip to content

トピトピニュース

Header Image
Archive

Month: May 2022

251 Posts

Featured

Posted byByakuya Biz Books
シンガポール発のコーヒーチェーン「フラッシュコーヒー」が2年で250店舗に拡大した理由
Posted byGoogle Japan Blog
個人情報を考える週間: パスワードとオンライン アカウントを安全に保つためのヒント
Posted byねっと特報
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byFunglr Games(日本語)
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!

[org.jenkins-ci.plugins:active-directory] Authentication cache in Active Directory Jenkins Plugin allows logging in with any password

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/09/2022

Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode.
References

https://nvd.nist.gov/vuln/…

[org.jenkins-ci.plugins:active-directory] Improper Authentication (empty password) in Jenkins Active Directory Plugin

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/08/2022

Jenkins Active Directory Plugin prior to 2.20 does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.
References

https:…

[org.jenkins-ci.plugins:active-directory] Improper Authentication in Jenkins Active Directory Plugin

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/08/2022

Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2299
https://www.jenkins.io/security/advisory/2020-11-04/#SECURIT…

[Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64] Integer overflow in the bundled Brotli C library

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/01/2022

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a “one-shot” decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 Gi…

[Microsoft.AspNetCore.Http] Cookie parsing failure

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/24/2022

A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being …

[expo] Expo on iOS is insecure due incorrect security attribute application

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202209/16/2022

secure-store in Expo through 9.1.0 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-24653
https://github.com/expo/expo/pull/926…

[Microsoft.AspNetCore.App.Runtime.linux-arm] ASP.NET Core Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/25/2022

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka ASP.NET Core Denial of Service Vulnerability.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-1597
https://lists.fedoraproject.org/archives/list/packa…

[org.jenkins-ci.main:jenkins-core] Improper Neutralization of Input During Web Page Generation in Jenkins

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/01/2022

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via ‘Trigger builds remotely’, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure per…

[org.jenkins-ci.main:jenkins-core] Improper Neutralization of Input During Web Page Generation in Jenkins

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202210/07/2022

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2229
https://jenkins.io/security…

[org.jenkins-ci.main:jenkins-core] Improper Neutralization of Input During Web Page Generation in Jenkins

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202210/07/2022

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
References

https://nvd.nist…

Posts navigation

Previous Posts 1 2 3 4 5 6 … 26 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close