Skip to content

TechMedia

Header Image
Archive

Month: May 2022

376 Posts

Featured

Posted byWpmaster
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byWpmaster
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!
Posted byWpmaster
高橋幸宏、ソロ活動50周年記念!『T.E.N.T Years Vinyl Box』収録ライブ音源の詳細発表!
Posted byWpmaster
[camaleon_cms] Camaleon CMS Stored Cross-site Scripting vulnerability

[org.jenkins-ci.plugins:gitlab-oauth] Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/29/2022

GitLab Authentication Plugin 1.5 and earlier does not differentiate between user names and hierarchical group names when performing authorization. This allows an attacker with permissions to create groups in GitLab to gain the privileges granted to ano…

[org.jenkins-ci.main:jenkins-core] Stored XSS vulnerability in Jenkins ‘keep forever’ badge icon

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/28/2022

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the ‘Keep this build forever’ badge tooltip. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users able to configure job names.
As job n…

[org.jenkins-ci.main:jenkins-core] Stored XSS vulnerability in Jenkins console links

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/28/2022

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the href attribute of links to downstream jobs displayed in the build console page. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Confi…

[org.jenkins-ci.main:jenkins-core] Stored XSS vulnerability in Jenkins upstream cause

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/28/2022

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job’s display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
Jenkins 2.245, LTS 2.235.2 escapes the job display name.
Refere…

[org.jenkins-ci.main:jenkins-core] Stored XSS vulnerability in Jenkins job build time trend

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/28/2022

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
Jenkins 2.245, LTS 2.235.2 escapes the agent name.
References

https://nvd.nist.go…

[org.jenkins-ci.plugins:fortify-on-demand-uploader] Users with Overall/Read access could enumerate credentials IDs in Jenkins Fortify on Demand Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

Fortify on Demand Plugin provides a list of applicable credentials IDs to allow users configuring the plugin to select the one to use.
This functionality does not correctly check permissions in Fortify on Demand Plugin 6.0.0 and earlier, allowing any u…

[org.jenkins-ci.plugins:sonargraph-integration] Stored XSS vulnerability in Jenkins Sonargraph Integration Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation.
This results in a stored cross-site scripting (XSS) vulnerability that can be exploited by users with Job/Configure permission.
Sonarg…

[org.jenkins-ci.plugins:fortify-on-demand-uploader] CSRF vulnerability in Jenkins Fortify on Demand Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.
This form validation method req…

[hudson.plugins:project-inheritance] Missing permission check in Jenkins Project Inheritance Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/22/2022

Jenkins Project Inheritance Plugin 21.04.03 and earlier does not redact encrypted secrets in the ‘getConfigAsXML’ API URL when transmitting job config.xml data to users without Job/Configure.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2198
h…

[hudson.plugins:project-inheritance] Missing permission check in Jenkins Project Inheritance Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/22/2022

Jenkins limits access to job configuration XML data (config.xml) to users with Job/ExtendedRead permission, typically implied by Job/Configure permission. Project Inheritance Plugin has several job inspection features, including the API URL /job/…​/get…

Posts navigation

Previous Posts 1 … 15 16 17 18 19 … 38 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close