Skip to content

トピトピニュース

Header Image

[org.jvnet.hudson.plugins:hipchat] Jenkins HipChat Plugin allows attackers with Overall/Read access to obtain credential IDs

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/23/2022

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins. As of version 2.2.1, an enume…

[org.apache.geode:geode-core] Apache Geode vulnerable to Incorrect Authorization

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/08/2022

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be …

[io.jenkins.blueocean:blueocean] Missing Authorization in Jenkins Blue Ocean Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/02/2022

The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.
References

https://nvd.nist.gov/vuln/d…

[org.richfaces:richfaces-core] Richfaces vulnerable to arbitrary code execution

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/13/202211/08/2022

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via or…

[org.jenkins-ci.main:jenkins-core] Incorrect Authorization in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/09/2022

Jenkins before versions before 2.44 are vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenki…

[org.apache.struts:struts2-core] Code injection in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/12/2022

A vulnerability introduced by forcing parameter inclusion in the URL and Anchor Tag allows remote command execution, session access and manipulation and XSS attacks.
both the s:url and s:a tag provide an includeParams attribute.
The main scope of that …

[org.apache.struts:struts2-core] Server side object manipulation in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/13/202211/04/2022

OGNL provides, among other features, extensive expression evaluation capabilities. This vulnerability allows a malicious user to bypass the ‘#’-usage protection built into the ParametersInterceptor, thus being able to manipulate server side context obj…

[org.apache.struts:struts2-core] Code injection in Apache Struts

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202211/04/2022

The Struts 2 DefaultActionMapper supports a method for short-circuit navigation state changes by prefixing parameters with “action:” or “redirect:”, followed by a desired navigational target expression. This mechanism was intended to help with attachin…

[oauthenticator] JupyterHub OAuthenticator elevation of privilege

  • Posted inHIGH
  • Posted byGitHub
  • 05/13/202209/13/2022

An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in…

[org.apache.activemq:activemq-openwire-generator] ActiveMQ’s OpenWire protocol exposes certain system details as plain text

  • Posted inLOW
  • Posted byGitHub
  • 05/13/202211/23/2022

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-15709
https://lists.apa…

Posts navigation

Previous Posts 1 … 86,785 86,786 86,787 86,788 86,789 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close