Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[org.jenkins-ci.plugins:view26] Jenkins View26 Test-Reporting Plugin improperly validates hostname

  • Posted inHIGH
  • Posted byGitHub
  • 09/22/202209/23/2022

Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.
References

https://nvd.ni…

[org.jenkins-ci.plugins:bigpanda-jenkins] Jenkins BigPanda Notifier Plugin stores BigPanda API key unencrypted

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/24/2022

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
References

https…

[org.jenkins-ci.plugins:extreme-feedback] Jenkins extreme-feedback Plugin vulnerable to Missing Authorization

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/23/2022

A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.
Re…

[com.smalltest:smalltest] Jenkins SmallTest Plugin improperly validates hostname

  • Posted inHIGH
  • Posted byGitHub
  • 09/22/202209/23/2022

Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.
References

https://nvd.nist.gov/vuln/…

[net.praqma:rqm-plugin] Jenkins RQM Plugin vulnerable to Improper Restriction of XML External Entity Reference

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/22/202209/23/2022

Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-41241
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2805
https://gi…

[org.jenkins-ci.plugins:rundeck] Jenkins Rundeck Plugin Missing Authorization vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 09/22/202209/23/2022

Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permission to trigger jobs that are configured to be triggerable via Rundeck.
References

https://nvd.nist.gov/…

[io.jenkins.plugins:cavisson-ns-nd-integration] Jenkins NS-ND Integration Performance Publisher Plugin vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/23/2022

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers…

[io.jenkins.plugins:cavisson-ns-nd-integration] Jenkins NS-ND Integration Performance Publisher Plugin vulnerable to Cross-Site Request Forgery

  • Posted inHIGH
  • Posted byGitHub
  • 09/22/202209/23/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials. Version 4.8.0.130 req…

[org.jenkins-ci.plugins:wildfly-deployer] Jenkins WildFly Deployer Plugin vulnerable to path traversal

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/24/2022

Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-41235
https://www.jenkins.io/sec…

[craftcms/cms] Craft CMS Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 09/22/202209/24/2022

Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-37246
https://github….

Posts navigation

Previous Posts 1 … 47 48 49 50 51 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close