Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[org.jenkins-ci.plugins:JiraTestResultReporter] CSRF vulnerability and missing permission check in Jenkins JiraTestResultReporter Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
References

https://nvd.nist.gov/vul…

[io.jenkins.plugins:atlassian-bitbucket-server-integration] Missing permission checks in Jekins Bitbucket Server Integration Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
References

https://nvd….

[org.jenkins-ci.plugins:JiraTestResultReporter] Missing permission check in Jenkins JiraTestResultReporter Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
References

https://nvd.nist.g…

[org.jenkins-ci.plugins:rocketchatnotifier] CSRF vulnerability in Jenkins RocketChat Notifier Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/30/202211/30/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[paramiko] Race Condition in Paramiko

  • Posted inMODERATE
  • Posted byGitHub
  • 03/19/202209/15/2022

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-24302
https://github.com/paramiko/par…

[org.jenkins-ci.plugins:release-helper] CSRF vulnerability in Jenkins Release Helper Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/16/202212/01/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-27…

[org.jenkins-ci.plugins:release-helper] Missing permission checks in Jenkins Release Helper Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/16/202212/01/2022

A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
References

https://nvd.nist.gov/vuln/detail/CVE-2…

[com.incapptic.plugins:incapptic-connect-uploader] Personal tokens stored in plain text by Jenkins incapptic connect uploader Plugin

  • Posted inMODERATE
  • Posted byGitHub
  • 03/16/202212/01/2022

Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Ref…

[xerces:xercesImpl] Improper Input Validation in Xerces

  • Posted inMODERATE
  • Posted byGitHub
  • 02/15/202212/01/2022

A flaw was found in Wildfly’s implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the “use-grammar-pool-only” feature. This flaw allows a specially-crafted XML file to manipulate the …

[org.jenkins-ci.main:jenkins-core] DoS vulnerability in bundled XStream library in Jenkins Core

  • Posted inMODERATE
  • Posted byGitHub
  • 02/10/202211/30/2022

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier is affected by the XStream library’s vulnerability CVE-2021-43859. This library is used by Jenkins to serialize and deserialize various XML files, like global and job config.xml, build.xml, and numerou…

Posts navigation

Previous Posts 1 … 45 46 47 48 49 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close