かつてMicrosoft(以下、「MS」)のSurfaceシリーズは修理しにくいことに定評がありまし…
1972年に生まれたベスト・ソング : 50年前に作られた67の名曲をランキング
1972年にリリースされた曲について、何を語ればいいだろう?この時期は、世界中の一流ミュージシャンが…
[io.loader:loaderio-jenkins-plugin] Missing permission check in Jenkins loader.io Plugin allows enumerating credentials IDs
loader.io Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capt…
[org.jenkins-ci.plugins:delete-log-plugin] Missing permission check in Jenkins Delete log Plugin
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs. As of publication of this advisory, there is no fix.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-45394
ht…
[org.jenkins-ci.main:associated-files-plugin] Jenkins Associated Files Plugin vulnerable to cross-site scripting (XSS)
Jenkins Associated Files Plugin 0.2.1 and earlier does not escape names of associated files, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. Currently, there are no known workaroun…
[org.jenkins-ci.plugins:bart] Jenkins BART Plugin vulnerable to cross-site scripting (XSS)
Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability. Currently, there are no known workarounds or patches available…
[io.jenkins.plugins:cavisson-ns-nd-integration] SSL/TLS certificate validation globally and unconditionally disabled by Jenkins NS-ND Integration Performance Publisher Plugin
NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.
NS-ND Integration Performance Publisher Plugin 4.8.0.146 no lo…
[org.jenkins-ci.plugins:dockerhub-notification] Lack of authentication mechanism for webhook in CloudBees Docker Hub/Registry Notification Plugin
CloudBees Docker Hub/Registry Notification Plugin provides several webhook endpoints that can be used to trigger builds when Docker images used by a job have been rebuilt.
In CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier, these en…
[org.jenkins-ci.main:config-rotator] Jenkins Config Rotator Plugin vulnerable to path traversal
Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with ‘.xml’ extension on the Jenkins controller file system. Currently there i…
[io.jenkins.plugins:cavisson-ns-nd-integration] Plaintext Storage of a Password in Jenkins NS-ND Integration Performance Publisher Plugin
NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller as part of its configuration.
These passwords can be viewed by attackers with Item/Extended Read permiss…