Skip to content

TechMedia

Header Image
Author

wpmaster

811184 Posts

Featured

Posted byWpmaster
大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
Posted byWpmaster
サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
Posted byWpmaster
吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
Posted byWpmaster
【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)

Logitech Gのクラウド携帯ゲーム機『Cloud』正式発表。12時間駆動で350ドルのAndroid端末

  • Posted inUncategorized
  • Posted byWpmaster
  • 09/22/2022

Logitech が漏れまくっていたクラウド携帯ゲーム機を正式発表しました。名称はシンプルに『Clo…

【ハンズオンレビュー】Samsung Galaxy Z Flip 4

  • Posted inUncategorized
  • Posted byWpmaster
  • 09/22/2022

Z Flip 3ユーザーも予算に余裕があるなら買い換える価値あり! Samsung Galaxy Z…

[org.jenkins-ci.main:jenkins-core] Jenkins vulnerable to stored cross site scripting in the I:helpIcon component

  • Posted inHIGH
  • Posted byWpmaster
  • 09/22/202212/15/2022

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control…

[org.jenkins-ci.plugins:ws-execution-manager] CSRF vulnerability and mM

  • Posted inMODERATE
  • Posted byWpmaster
  • 09/22/202212/12/2022

Worksoft Execution Manager Plugin 10.0.3.503 and earlier does not perform a permission check in a method implementing form validation.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified c…

[org.jenkins-ci.plugins:rundeck] Missing webhook endpoint authorization in Jenkins Rundeck Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 09/22/202212/09/2022

Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permission to trigger jobs that are configured to be triggerable via Rundeck.
References

https://nvd.nist.gov/…

[org.jenkins-ci.plugins:ws-execution-manager] CSRF vulnerability in Jenkins Worksoft Execution Manager Plugin allows capturing credentials

  • Posted inMODERATE
  • Posted byWpmaster
  • 09/22/202212/07/2022

Worksoft Execution Manager Plugin 10.0.3.503 and earlier does not perform a permission check in a method implementing form validation. This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified c…

[com.groupon.jenkins-ci.plugins:DotCi] Stored XSS vulnerability in Jenkins DotCi Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 09/22/202212/07/2022

DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to s…

[com.groupon.jenkins-ci.plugins:DotCi] Lack of authentication mechanism in Jenkins DotCi Plugin webhook

  • Posted inMODERATE
  • Posted byWpmaster
  • 09/22/202212/07/2022

DotCi Plugin provides a webhook endpoint at /githook/ that can be used to trigger builds of the job for a GitHub repository.
In DotCi Plugin 2.40.00 and earlier, this endpoint can be accessed without authentication.
This allows unauthenticated attacker…

[org.jenkins-ci.plugins:walti] Stored XSS vulnerability in Jenkins Walti plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 09/22/202212/07/2022

Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.
References

ht…

[org.jenkins-ci.plugins:security-inspector] CSRF vulnerability in Jenkins Security Inspector plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 09/22/202212/07/2022

Security Inspector Plugin 117.v6eecc36919c2 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to replace the generated report stored in a…

Posts navigation

Previous Posts 1 … 81,042 81,043 81,044 81,045 81,046 … 81,119 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close