Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[com.compuware.jenkins:compuware-topaz-for-total-test] Jenkins Compuware Topaz for Total Test Plugin vulnerable to Protection Mechanism Failure

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller fi…

[com.compuware.jenkins:compuware-strobe-measurement] Jenkins Compuware Strobe Measurement Plugin Missing Authorization vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
References

https://nv…

[com.compuware.jenkins:compuware-topaz-for-total-test] Jenkins Compuware Topaz for Total Test Plugin vulnerable to Protection Mechanism Failure

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from …

[io.jenkins.plugins:screenrecorder] Jenkins ScreenRecorder Plugin disables Content-Security-Policy protection for user-generated content

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
References

https://nvd.nist.gov/vuln/detail…

[org.jenkins-ci.plugins:xframium] Jenkins XFramium Builder Plugin disables Content-Security-Policy protection for user-generated content

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

Jenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
References

https://nvd.nist.gov/vuln/d…

[org.jenkins-ci.plugins:nunit] Jenkins NUnit Plugin vulnerable to Protection Mechanism Failure

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/21/2022

Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test results from files in an attacker-spe…

[com.compuware.jenkins:compuware-scm-downloader] Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin vulnerable to Protection Mechanism Failure

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of …

[org.jenkins-ci.plugins.workflow:workflow-support] Jenkins Pipeline: Supporting APIs Plugin vulnerable to stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/22/2022

Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacke…

[org.jenkins-ci.plugins.workflow:workflow-cps-global-lib] Jenkins Pipeline: Deprecated Groovy Libraries Plugin vulnerable to Protection Mechanism Failure

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, …

[o.jenkins.plugins:pipeline-groovy-lib] Jenkins Pipeline: Groovy Libraries Plugin vulnerable to Protection Mechanism Failure

  • Posted inMODERATE
  • Posted byGitHub
  • 10/20/202210/20/2022

A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass t…

Posts navigation

Previous Posts 1 … 12 13 14 15 16 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close