Skip to content

トピトピニュース

Header Image

[org.jenkins-ci.main:jenkins-core] Cross-site Scripting in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
References…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information in Jenkins Core

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.
References

https://nvd.nist.gov/vuln/d…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
References

https://nvd.nist…

[org.jenkins-ci.main:jenkins-core] Missing permissions check in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (s…

[org.jenkins-ci.main:jenkins-core] Incorrect Authorization in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the “full name.”
References

https://nvd.nist.gov/vuln/detail/CVE-2016-3722
https://access.redha…

[org.apache.drill:drill-common] Apache Drill vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/08/2022

In Apache Drill 1.11.0 and earlier, when submitting form from Query page, users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Q…

[commons-fileupload:commons-fileupload] Arbitrary file write in Apache Commons Fileupload

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/04/2022

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in …

[edu.internet2.middleware:shibboleth-identityprovider] Improper Certificate Validation in vt-ldap

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject’s Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL serve…

[org.apache.geode:geode-core] Apache Geode gfsh authorization vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/14/202211/08/2022

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:M…

Posts navigation

Previous Posts 1 … 86,774 86,775 86,776 86,777 86,778 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close