Skip to content

トピトピニュース

Header Image

[org.apache.solr:solr-core] Apache Solr vulnerable to XML Bomb

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/08/2022

Solr versions prior to 5.0.0 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it?s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses t…

[com.github.kevinsawicki:http-request] Missing certificate validation

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/04/2022

OSS Http Request (kevinsawicki/http-request) is missing SSL/TLS certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.
References

https://nv…

[org.jenkins-ci.plugins:gitea] Improper handling of untrusted branches in Gitea Jenkins Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202209/15/2022

Jenkins Gitea Plugin prior to 1.1.2 did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
References

https://nvd.nist.gov/vu…

[org.jenkins-ci.plugins:influxdb] Plaintext password storage in Jenkins InfluxDB Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202209/09/2022

Jenkins InfluxDB Plugin Prior to 1.22 stored credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-1…

[org.jenkins-ci.plugins:pipeline-maven] XML External Entity processing vulnerability in Pipeline Maven Integration Jenkins Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202209/09/2022

An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory’s content on the agent running the Maven build to have Jenkins parse a maliciously craft…

[Microsoft.ChakraCore] Chakra Scripting Engine and ChakraCore Vulnerable to Memory Corruption

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202208/31/2022

Chakra Scripting Engine and ChakraCore are vulnerable to memory corruption due to an out-of-bounds write. The Microsoft advisory for CVE-2021-42279 was modified in August 2022 to include Microsoft.ChakraCore as an affected product.
References

https://…

[org.jenkins-ci.main:jenkins-core] Improper Authorization in Jenkins

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202210/26/2022

When creating temporary files, agent-to-controller access to create those files is only checked after they’ve been created in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-21693
https://www.je…

[org.jenkins-ci.main:jenkins-core] Missing Authorization in Jenkins

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202210/26/2022

FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-21689
https://www.jenkins.io/security/advisory/202…

[org.jenkins-ci.main:jenkins-core] Missing Authorization in Jenkins

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/26/2022

FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-21695
https://www.jenkins.io…

[apache-airflow] Missing Authentication for Critical Function in Apache Airflow

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/21/2022

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, infor…

Posts navigation

Previous Posts 1 … 86,764 86,765 86,766 86,767 86,768 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close