Skip to content

トピトピニュース

Header Image

[io.jenkins.plugins:atlassian-bitbucket-server-integration] Stored XSS vulnerability in Jenkins Bitbucket Server Integration Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 03/30/202211/30/2022

Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consu…

[org.jenkins-ci.plugins:proxmox] Password stored in plain text by Jenkins Proxmox Plugin

  • Posted inLOW
  • Posted byGitHub
  • 03/30/202211/30/2022

Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
References

https://n…

[org.jenkins-ci.plugins:rocketchatnotifier] CSRF vulnerability in Jenkins RocketChat Notifier Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[org.jenkins-ci.plugins:JiraTestResultReporter] Missing permission check in Jenkins JiraTestResultReporter Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
References

https://nvd.nist.g…

[org.jvnet.hudson.plugins:instant-messaging] Plaintext storage in Jenkins instant-messaging Plugin

  • Posted inLOW
  • Posted byGitHub
  • 03/30/202211/30/2022

Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access…

[io.jenkins.plugins:atlassian-bitbucket-server-integration] Missing permission checks in Jekins Bitbucket Server Integration Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
References

https://nvd….

[org.jenkins-ci.plugins:JiraTestResultReporter] CSRF vulnerability and missing permission check in Jenkins JiraTestResultReporter Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
References

https://nvd.nist.gov/vul…

[org.jenkins-ci.plugins:rocketchatnotifier] Missing permission check in Jenkins RocketChat Notifier Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

RocketChat Notifier Plugin 1.4.10 and earlier does not perform a permission check in a method implementing form validation.This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and …

[org.jenkins-ci.plugins:ci-with-toad-edge] Cross-site Scripting (XSS) vulnerability in Jenkins Continuous Integration with Toad Edge Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 03/30/202211/30/2022

Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to report files it serves, resulting in a stored cross-site scripting (XSS) exploitable by attackers with Item/Configure permission or o…

GOP Rep. Darrell Issa Files Preservation Letters On Hunter Biden’s Laptop

  • Posted inUncategorized
  • Posted byUPolitics.com
  • 03/30/2022

Republican Rep. Darrell Issa (California) criticized Democrats and the media for censoring coverage of Hunter Biden‘s laptop to protect and help President Joe Biden win the 2020 Election. The accusation came three days after Rep. Elyse Stefanik (R-New …

Posts navigation

Previous Posts 1 … 86,790 86,791 86,792 86,793 86,794 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close