Skip to content

TechMedia

Header Image
Archive

Month: May 2022

376 Posts

Featured

Posted byWpmaster
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byWpmaster
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!
Posted byWpmaster
高橋幸宏、ソロ活動50周年記念!『T.E.N.T Years Vinyl Box』収録ライブ音源の詳細発表!
Posted byWpmaster
[camaleon_cms] Camaleon CMS Stored Cross-site Scripting vulnerability

[org.jenkins-ci.plugins:electricflow] Missing permission check in CloudBees CD Plugin allows scheduling builds

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Item/Read permission to schedule builds of projects without having Item/Build permission.
CloudBees CD Plugin 1.1.22 requires Ite…

[org.jenkins-ci.plugins:config-file-provider] CSRF vulnerability in Jenkins Config File Provider Plugin allows deleting configuration files

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

Config File Provider Plugin 3.7.0 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to delete configuration files corresponding to an att…

[org.jenkins-ci.plugins:hp-application-automation-tools-plugin] Missing permission checks in Micro Focus Application Automation Tools Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

Micro Focus Application Automation Tools Plugin 6.7 and earlier does not perform permission checks in methods implementing form validation.
This allows attackers with Overall/Read permission to connect to attacker-specified URLs using attacker-specifie…

[org.jenkins-ci.plugins:hp-application-automation-tools-plugin] SSL/TLS certificate validation unconditionally disabled by Jenkins Micro Focus Application Automation Tools Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

Micro Focus Application Automation Tools Plugin 6.7 and earlier unconditionally disables SSL/TLS certificate validation for connections to Service Virtualization servers.
Micro Focus Application Automation Tools Plugin 6.8 no longer disables SSL/TLS ce…

[org.jenkins-ci.plugins:hp-application-automation-tools-plugin] Reflected XSS vulnerability in Jenkins Micro Focus Application Automation Tools Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/14/2022

Micro Focus Application Automation Tools Plugin 6.7 and earlier does not escape user input in a form validation response.
This results in a reflected cross-site scripting (XSS) vulnerability.
Micro Focus Application Automation Tools Plugin 6.8 escapes …

[org.jenkins-ci.plugins:hp-application-automation-tools-plugin] CSRF vulnerability in Jenkins Micro Focus Application Automation Tools Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

Micro Focus Application Automation Tools Plugin 6.7 and earlier does not perform permission checks in methods implementing form validation.
This allows attackers with Overall/Read permission to connect to attacker-specified URLs using attacker-specifie…

[org.jenkins-ci.main:jenkins-core] View name validation bypass in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name. When a form to create a view is submitted, the name is included twice in the submission. One instance is validated, but the other …

[org.jenkins-ci.plugins:promoted-builds] CSRF vulnerability in Jenkins promoted builds Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

promoted builds Plugin 3.9 and earlier does not require POST requests for HTTP endpoints implementing promotion (regular, forced, and re-execute), resulting in cross-site request forgery (CSRF) vulnerabilities.
These vulnerabilities allow attackers to …

[org.jenkins-ci.main:jenkins-core] Improper Input Validation in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the config.xml REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with…

[org.jvnet.hudson.plugins:jabber] Passwords stored in plain text by Jenkins Jabber (XMPP) notifier and control Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/16/2022

Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file hudson.plugins.jabber.im.transport.JabberPublisher.xml on the Jenkins controller as part of its configuration.
These passwords can …

Posts navigation

Previous Posts 1 … 3 4 5 6 7 … 38 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close