Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[org.apache.struts:struts2-core] Possible DoS attack when using URLValidator

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
References

https://nvd.nist.gov/vuln/…

[org.jvnet.hudson.plugins:groovy-postbuild] Jenkins Groovy Postbuild Plugin vulnerable to Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/23/2022

A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user’s brow…

[org.csanchez.jenkins.plugins:kubernetes] Exposure of Sensitive Information in Jenkins Kubernetes Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.
References

https://nvd.nist.gov/vuln/deta…

[net.opentsdb:opentsdb] OpenTSDB Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/23/2022

An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter json to the /q URI.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-12973
https://github.com/OpenTSDB/opentsdb/issues/1240
https://github.com/advisories/GHSA-r68m-wq3x-2hqw

[io.jenkins:configuration-as-code] Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/09/2022

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration. Ve…

[com.amazonaws:codedeploy] Jenkins AWS CodeDeploy Plugin has Insufficiently Protected Credentials

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/08/2022

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to…

[org.graylog2:graylog2-server] Cross-site Scripting in Graylog Server

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/05/2022

In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-14380
https://github.com/Graylog2/graylog2-ser…

[org.elasticsearch:elasticsearch] Cross-site scripting in Elasticsearch

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-6439
ht…

[org.apache.struts:struts2-core] Cross-Site Request Forgery in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-7809
http://packetstormsecurity.com/f…

[struts:struts] Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 05/14/202211/04/2022

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cook…

Posts navigation

Previous Posts 1 … 40 41 42 43 44 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close