JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links.
This is done in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure p…
[org.jenkins-ci.plugins:script-security] Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions
Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the approved script. SHA-1 no longer meets the security standards for producing a cryptographically secure message digest.
Script Security Plugi…
[org.jenkins-ci.main:cavisson-ns-nd-integration] SSL/TLS certificate validation unconditionally disabled by Jenkins NS-ND Integration Performance Publisher Plugin
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features. Currently, there are no known workarounds or patches.
References
https://nvd.nist.g…
[org.jenkins-ci.plugins:support-core] Incorrect permission checks in Jenkins Support Core Plugin
Support Core Plugin defines the permission Support/DownloadBundle that allows users without Overall/Administer permission to create and download support bundles containing a limited set of diagnostic information.
Support Core Plugin 1206.v14049fa_b_d86…
[org.jenkins-ci.plugins:naginator] Cross-site Scripting in Jenkins Naginator Plugin
Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered via Retry action.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to edit build display nam…
[org.jenkins-ci.plugins:pipeline-utility-steps] Arbitrary file read vulnerability in Jenkins Pipeline Utility Steps Plugin
Pipeline Utility Steps Plugin implements a readProperties Pipeline step that supports interpolation of variables using the Apache Commons Configuration library.
Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefi…
[github.com/hashicorp/consul] Missing Authorization in HashiCorp Consul
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering’s imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-3920
https://discu…
【ダイソー】100円で“プロ級の写真”が撮れる!おすすめ撮影グッズをご紹介♪
ダイソーで買い物中、見つけた『撮影用ライト』。コロナでおうち時間が増え、フリマサイトに手を出している…
コードタクト、デジタル庁の実証調査研究に参加する事業者として採択
コードタクトは、同社が10月25日に、デジタル庁の「初等中等教育における校務支援システム、学習支援シ…
109シネマズプレミアム新宿、坂本龍一がシアター音響を監修 新宿ミラノ座跡地に来年開業
東京都新宿区歌舞伎町に2023年4月14日開業予定の「109シネマズプレミアム新宿」の全シアターの音…