Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
References

https://nvd.nist…

[org.jenkins-ci.main:jenkins-core] Incorrect Authorization in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the “full name.”
References

https://nvd.nist.gov/vuln/detail/CVE-2016-3722
https://access.redha…

[org.jenkins-ci.main:jenkins-core] Missing permissions check in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (s…

[org.apache.drill:drill-common] Apache Drill vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/08/2022

In Apache Drill 1.11.0 and earlier, when submitting form from Query page, users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Q…

[edu.internet2.middleware:shibboleth-identityprovider] Improper Certificate Validation in vt-ldap

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/02/2022

DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject’s Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL serve…

[org.apache.geode:geode-core] Apache Geode OQL bind parameter vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/08/2022

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within una…

[org.jvnet.hudson.plugins:swarm-plugin] Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/23/2022

Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.
References

https://nvd…

[org.graylog2:graylog2-server] Cross-site Scripting in Graylog Server

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/05/2022

Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-11650
https://github.com/Graylog2/graylog2-server/pull/4727
http…

[org.graylog2:graylog2-server] Cross-site Scripting in Graylog

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/05/2022

Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
References

https://nvd.nist.gov/vuln/d…

Posts navigation

Previous Posts 1 … 39 40 41 42 43 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close