Skip to content

TechMedia

Header Image
Archive

Month: July 2022

27 Posts

Featured

Posted byWpmaster
[mongoose] automattic/mongoose vulnerable to Prototype pollution via Schema.path
Posted byWpmaster
ウェブ向けプライバシー サンドボックスのテスト期間延長について
Posted byWpmaster
[eu.markov.jenkins.plugin.mvnmeta:maven-metadata-plugin] Stored XSS vulnerability in Jenkins Maven Metadata Plugin for Jenkins CI server plugin
Posted byWpmaster
[org.jenkins-ci.plugins:http_request] Jenkins HTTP Request Plugin stores HTTP Request passwords unencrypted

[net.praqma:rqm-plugin] Jenkins RQM Plugin allows enumerating credentials IDs due to missing permission check

  • Posted inMODERATE
  • Posted byWpmaster
  • 07/01/202212/09/2022

Jenkins RQM Plugin 2.8 and earlier does not perform a permission check in an HTTP endpoint. This allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capt…

[com.xebialabs.ci:xlrelease-plugin] CSRF vulnerability in Jenkins XebiaLabs XL Release Plugin allow capturing credentials

  • Posted inMODERATE
  • Posted byWpmaster
  • 07/01/202212/13/2022

XebiaLabs XL Release Plugin 22.0.0 and earlier does not perform permission checks in methods implementing form validation.
This allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified crede…

[net.praqma:matrix-reloaded] Jenkins Matrix Reloaded Plugin vulnerable to Stored XSS

  • Posted inHIGH
  • Posted byWpmaster
  • 07/01/202212/09/2022

Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
References

https://nvd.nist.gov/vuln/…

[com.xebialabs.ci:xlrelease-plugin] Missing permission checks in Jenkins XebiaLabs XL Release Plugin allow capturing credentials

  • Posted inMODERATE
  • Posted byWpmaster
  • 07/01/202212/09/2022

Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, c…

[hudson.plugins:project-inheritance] Jenkins Project Inheritance Plugin vulnerable to cross site scripting

  • Posted inHIGH
  • Posted byWpmaster
  • 07/01/202212/09/2022

Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.
Refe…

[net.praqma:matrix-reloaded] Jenkins Matrix Reloaded Plugin vulnerable to CSRF

  • Posted inMODERATE
  • Posted byWpmaster
  • 07/01/202212/09/2022

Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to rebuild previous matrix builds.
References

htt…

[org.jenkins-ci.plugins:plot] Cross-site Scripting in Jenkins Plot Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 07/01/202212/09/2022

Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3478…

Posts navigation

Previous Posts 1 2 3
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close