Skip to content

TechMedia

Header Image
Archive

Month: May 2022

376 Posts

Featured

Posted byWpmaster
ウクライナ戦争に見るワイパー攻撃の実態とデジタル情報操作
Posted byWpmaster
「エースコンバット」と「トップガン マーヴェリック」が夢のコラボ!マーヴェリックスキンの「F-14A Tomcat」や「F/A-18E Super Hornet」が登場!
Posted byWpmaster
高橋幸宏、ソロ活動50周年記念!『T.E.N.T Years Vinyl Box』収録ライブ音源の詳細発表!
Posted byWpmaster
[camaleon_cms] Camaleon CMS Stored Cross-site Scripting vulnerability

[org.jenkins-ci.main:jenkins-core] Reflected XSS vulnerability in Jenkins markup formatter preview

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/13/2022

Jenkins allows administrators to choose the markup formatter to use for descriptions of jobs, builds, views, etc. displayed in Jenkins. When editing such a description, users can choose to have Jenkins render a formatted preview of the description they…

[org.jenkins-ci.main:jenkins-core] Stored XSS vulnerability in Jenkins on new item page

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/13/2022

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names …

[org.jenkins-ci.main:jenkins-core] Arbitrary file read vulnerability in workspace browsers in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

The file browser for workspaces, archived artifacts, and $JENKINS_HOME/userContent/ follows symbolic links to locations outside the directory being browsed in Jenkins 2.274 and earlier, LTS 2.263.1 and earlier.
This allows attackers with Job/Workspace …

[org.jenkins-ci.main:jenkins-core] Arbitrary file existence check in file fingerprints in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins provides a feature for jobs to store and track fingerprints of files used during a build. Jenkins 2.274 and earlier, LTS 2.263.1 and earlier provides a REST API to check where a given fingerprint was used by which builds. This endpoint does not…

[org.jenkins-ci.main:jenkins-core] Missing permission check for paths with specific prefix in Jenkins

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins includes a static list of URLs that are always accessible even without Overall/Read permission, such as the login form. These URLs are excluded from an otherwise universal permission check.
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier doe…

[org.jenkins-ci.main:jenkins-core] Improper handling of REST API XML deserialization errors in Jenkins

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins provides XML REST APIs to configure views, jobs, and other items. When deserialization fails because of invalid data, Jenkins 2.274 and earlier, LTS 2.263.1 and earlier stores invalid object references created through these endpoints in the Old…

[Microsoft.AspNetCore.App.Runtime.linux-musl-arm] ASP.NET Core and Visual Studio Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202211/04/2022

A denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade.
References

https://nvd.nist.gov/vul…

[org.jenkins-ci.plugins:cvs] XXE vulnerability in Jenkins CVS Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/24/2022

CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows attackers able to control an agent process to have Jenkins parse a crafted changelog file that uses external entities for extraction…

[io.jenkins.plugins:chaos-monkey] Missing permission checks in Jenkins Chaos Monkey Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/24/2022

Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to generate load and to generate memory leaks.
Chaos Monkey Plugin 0.4 requires Overall/Administer perm…

[io.jenkins.plugins:chaos-monkey] Missing permission checks in Jenkins Chaos Monkey Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/17/2022

Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint.
This allows attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.
Chaos Monkey Plugin 0.4.1 requires Overall…

Posts navigation

Previous Posts 1 … 6 7 8 9 10 … 38 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close