Skip to content

TechMedia

Header Image
Archive

Month: May 2022

376 Posts

Featured

Posted byWpmaster
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byWpmaster
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!
Posted byWpmaster
高橋幸宏、ソロ活動50周年記念!『T.E.N.T Years Vinyl Box』収録ライブ音源の詳細発表!
Posted byWpmaster
[camaleon_cms] Camaleon CMS Stored Cross-site Scripting vulnerability

[org.jenkins-ci.plugins:coverity] Jenkins Coverity Plugin has Insufficiently Protected Credentials

  • Posted inLOW
  • Posted byWpmaster
  • 05/13/202212/08/2022

A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator’s web browser (e.g. malicious extension…

[org.jenkins-ci.plugins:google-play-android-publisher] Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/08/2022

An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs. As of version 1.7, enumeration of credentials …

[org.jenkins-ci.plugins:build-publisher] Jenkins Build-Publisher plugin has Insufficiently Protected Credentials

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowin…

[org.jenkins-ci.plugins:parameterized-trigger] Parameterized Trigger Plugin fails to check Item/Build permission

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins. The plugin has been adapted to now check f…

[hammer_cli_foreman] hammer_cli_foreman Improper Certificate Validation vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202201/27/2023

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle …

[katello] katello Improper Privilege Management vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A flaw was found in Foreman’s katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the r…

[katello] katello SQL Injection vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A SQL injection flaw was found in katello’s errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix fo…

[org.jenkins-ci.plugins:jira] Jenkins Jira Plugin Incorrect Authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtain…

[org.jenkins-ci.plugins:ansible] Jenkins Ansible Plugin man in the middle vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybo…

[org.jenkins-ci.plugins:jenkins-multijob-plugin] Jenkins Multijob plugin did not check permissions in the Resume Build action

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build. Multijob plugin 1.26 introduced a permission check requiring Overall/Administer. This w…

Posts navigation

Previous Posts 1 … 34 35 36 37 38 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close