Skip to content

トピトピニュース

Header Image

[io.alauda.jenkins.plugins:alauda-kubernetes-support] Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/04/2022

A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capt…

[io.alauda.jenkins.plugins:alauda-kubernetes-support] Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/04/2022

A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kub…

[tech.andrey.jenkins:mission-control-view] Cross site scripting in Jenkins Mission Control Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/02/2022

Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change these properties.
References

https://nvd.nist.gov/vu…

[com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer] Missing permission check in Jenkins Build Failure Analyzer Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/09/2022

A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression.
References

https://nvd.nist.gov/vuln/detail/C…

[com.redgate.plugins.redgatesqlci:redgate-sql-ci] Jenkins Redgate SQL Change Automation Plugin has Insufficiently Protected Credentials

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/08/2022

Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
References…

[com.inflectra.spiratest.plugins:inflectra-spira-integration] Improper Certificate Validation in Jenkins Spira Importer Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/02/2022

Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-16558
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1580
http://www.op…

[katello] Katello cleartext password storage issue

  • Posted inLOW
  • Posted byGitHub
  • 05/25/202210/20/2022

A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.2. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credent…

[ansible] Ansible password prompts could expose passwords

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202210/08/2022

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to …

[pyarrow] Missing Initialization of Resource in Apache Arrow

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/10/2022

It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to uninitialized m…

[org.jenkins-ci.plugins.workflow:puppet-enterprise-pipeline] Incorrect Authorization in Puppet Enterprise Pipeline Jenkins Plugin

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/09/2022

Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.
References

https://nvd.nist.gov/vuln/…

Posts navigation

Previous Posts 1 … 86,768 86,769 86,770 86,771 86,772 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close