Skip to content

TechMedia

Header Image
Archive

Month: May 2022

376 Posts

Featured

Posted byWpmaster
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byWpmaster
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!
Posted byWpmaster
高橋幸宏、ソロ活動50周年記念!『T.E.N.T Years Vinyl Box』収録ライブ音源の詳細発表!
Posted byWpmaster
[camaleon_cms] Camaleon CMS Stored Cross-site Scripting vulnerability

[ember-source] Ember.js Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose cont…

[org.jenkins-ci.plugins:saml] Jenkins SAML Plugin Session Fixation vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session. SAML Plugin 1.0.7 invalidates…

[org.jenkins-ci.plugins:badge] Jenkins Badge Plugin cross-site scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in anot…

[xapian-core] xapian-core Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
References

https://nvd.nist.gov/vuln/detail/CVE-2018-0499
https://lists…

[org.jenkins-ci.plugins:meliora-testlab] Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key

  • Posted inLOW
  • Posted byWpmaster
  • 05/14/202212/13/2022

An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows attackers with file system access to the Jenkins master to obtain the API key stored in this plugin’s confi…

[org.jenkins-ci.plugins:collabnet] Jenkins CollabNet Plugin man in the middle vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to. CollabNet Plugin 2.0…

[fat_free_crm] Fat Free CRM Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/24/2023

Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account.
References

https://n…

[cakephp/cakephp] CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/14/2023

CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
References

https://nvd.nist.gov/vuln/detail/CVE-2015-8379
https://github.com/cakephp/cakephp/commit/0f818a23a876c01429196b…

[org.jenkins-ci.plugins:resource-disposer] Jenkins Resource Disposer Plugin allows attacker to stop tracking specified resource

  • Posted inLOW
  • Posted byWpmaster
  • 05/14/202212/13/2022

A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a specified resource. Additionally, this API endpoint did not require POST requests, resu…

[spree] Spree allows remote attackers to obtain sensitive information

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/produc…

Posts navigation

Previous Posts 1 … 32 33 34 35 36 … 38 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close