Skip to content

トピトピニュース

Header Image

[org.apache.jmeter:ApacheJMeter] Missing certificate validation in Apache JMeter

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/05/2022

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-1297
…

[org.apache.jmeter:ApacheJMeter] Missing certificate validation in Apache JMeter

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/05/2022

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. This only affect those running in Dist…

[org.grails.plugins:asset-pipeline] Asset Pipeline Grails Plugin vulnerable to Path Traversal

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/23/2022

Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in Download .class files and any arbitrary file. This att…

[io.jenkins:configuration-as-code] Jenkins Configuration as Code Plugin has Insufficiently Protected Credentials

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/09/2022

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to…

[com.amazonaws:aws-codepipeline] Jenkins AWS CodePipeline Plugin has Insufficiently Protected Credentials

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack appear to be exploitable via local …

[com.amazonaws:aws-codebuild] Insufficiently Protected Credentials in Jenkins AWS CodeBuild Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. This attack appear to be exploitab…

[com.synopsys.jenkinsci:ownership] Improper authorization in Jenkins Job and Node Ownership Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/04/2022

An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in
OwnershipDescription.java,
JobOwnerJobProperty.java,
and OwnerNodeProperty.java

that allow an attacker with Job/Configure or Computer/Con…

[org.apache.geode:geode-core] Apache Geode vulnerable to Exposure of Sensitive Information

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/08/2022

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In add…

[org.apache.openmeetings:openmeetings-parent] Apache OpenMeetings responds to insecure HTTP methods

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/30/2022

Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-7685
http://markmail.org/message/uxk4bpq35svnyjhb
http://www.securityfocus.com/bid/99592
http…

[org.apache.mesos:mesos] Denial of service in Apache Mesos

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/02/2022

When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos might crash because the code accidentally calls inappropriate function. A malicious actor can therefore cause a denial of service of Mesos masters …

Posts navigation

Previous Posts 1 … 86,781 86,782 86,783 86,784 86,785 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close