Skip to content

TechMedia

Header Image
Archive

Month: May 2022

376 Posts

Featured

Posted byWpmaster
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byWpmaster
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!
Posted byWpmaster
高橋幸宏、ソロ活動50周年記念!『T.E.N.T Years Vinyl Box』収録ライブ音源の詳細発表!
Posted byWpmaster
[camaleon_cms] Camaleon CMS Stored Cross-site Scripting vulnerability

[camaleon_cms] Camaleon CMS vulnerable to Uncaught Exception

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202201/25/2023

In Camaleon CMS, versions 2.0.1 through 2.6.0 are vulnerable to an Uncaught Exception. The app’s media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file.
References

https://nvd.nist….

[camaleon_cms] Camaleon CMS vulnerable to Server-Side Request Forgery

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202201/27/2023

In Camaleon CMS, versions 2.1.2.0 through 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or o…

[org.jenkins-ci.main:jenkins-core] Improper handling of equivalent directory names on Windows in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/16/2022

Jenkins stores jobs and other entities on disk using their name shown on the UI as file and folder names.
On Windows, when specifying a file or folder with a trailing dot character (example.), the file or folder will be treated as if that character was…

[org.jenkins-ci.main:jenkins-core] Path traversal vulnerability on Windows in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/16/2022

The file browser for workspaces, archived artifacts, and userContent/ in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows.
This results in a path traversal vulnerability allowing attackers with…

[org.jenkins-ci.plugins:git] Stored XSS vulnerability in Jenkins Git Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/16/2022

Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to su…

[org.jenkins-ci.plugins:nomad] Password stored in plain text by Jenkins Nomad Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/17/2022

Nomad Plugin 0.7.4 and earlier stores the passwords to authenticate against the Docker registry unencrypted in the global config.xml file on the Jenkins controller as part of its worker templates configuration.
These passwords can be viewed by users wi…

[smashing] Smashing Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202201/27/2023

Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaScript on the victim’s computer. The JavaScript code can then steal data available in the session/cookies depending on the user enviro…

[org.jenkins-ci.main:jenkins-core] Session fixation vulnerability in Jenkins

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/24/2022

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the existing session on login. This allows attackers to use social engineering techniques to gain administrator access to Jenkins.
This vulnerability was introduced in Jenkins 2.266…

[org.jenkins-ci.plugins:requests] CSRF vulnerabilities in Jenkins requests-plugin Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/17/2022

requests-plugin Plugin 2.2.12 and earlier does not require POST requests to request and apply changes, resulting in cross-site request forgery (CSRF) vulnerabilities.
These vulnerabilities allow attackers to create requests and/or have administrators a…

[org.jenkins-ci.main:jenkins-core] Improper permission checks allow canceling queue items and aborting builds in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/17/2022

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.
Jenkins 2.300, LTS 2.289.2 requires that users ha…

Posts navigation

Previous Posts 1 2 3 4 5 … 38 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close