Skip to content

トピトピニュース

Header Image

[org.jenkins-ci.plugins:batch-task] CSRF vulnerability in Jenkins batch task Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 01/13/202211/30/2022

Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve logs, build or delete a batch task.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-23115
https:…

[org.jenkins-ci.plugins:publish-over-ssh] Password stored in plain text by Jenkins Publish Over SSH Plugin

  • Posted inLOW
  • Posted byGitHub
  • 01/13/202211/30/2022

Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
References

https://nvd.nist.gov/…

[org.jenkins-ci.plugins:publish-over-ssh] Path traversal vulnerability in Jenkins Publish Over SSH Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 01/13/202211/30/2022

Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present or not, resulting in a path traversal vulnerability allowing attackers with Item/Configure permission to discover the name of the J…

[org.jenkins-ci.plugins:publish-over-ssh] CSRF vulnerability and missing permission checks in Jenkins Publish Over SSH Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 01/13/202211/30/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
References

https://nvd.nist.gov/vuln/detail/CVE…

[org.conjur.jenkins:conjur-credentials] Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows retrieving all credentials

  • Posted inMODERATE
  • Posted byGitHub
  • 01/13/202211/30/2022

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
References

https://nvd.nist.gov/vuln/detail/…

[org.conjur.jenkins:conjur-credentials] Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows decrypting secrets

  • Posted inMODERATE
  • Posted byGitHub
  • 01/13/202211/30/2022

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2…

[nemo-toolkit] Path Traversal in nemo-toolkit

  • Posted inMODERATE
  • Posted byGitHub
  • 01/11/202209/08/2022

NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available.
References

https://github.com/NVIDIA/NeMo/security/advisories/GHSA-rpx7-33j2-xx9x
h…

[k8s.io/kubernetes/pkg/kubectl] ANSI escape characters not filtered

  • Posted inLOW
  • Posted byGitHub
  • 01/08/202210/10/2022

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
References

https://nvd.nist.gov/vuln/detail…

チップセットが強化された新しいAcer Chromebook Spin 513が登場

  • Posted inUncategorized
  • Posted byUbergizmo Japan
  • 01/05/2022

通常、ディスプレイというと、より大きくなるほど高価になります。これは、モニターやテレビ、勿論ラップト…

[org.apache.logging.log4j:log4j-core] Improper Input Validation and Injection in Apache Log4j2

  • Posted inMODERATE
  • Posted byGitHub
  • 01/05/202210/06/2022

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to an attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JD…

Posts navigation

Previous Posts 1 … 86,798 86,799 86,800 86,801 86,802 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close