Skip to content

TechMedia

Header Image
Author

wpmaster

811184 Posts

Featured

Posted byWpmaster
大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
Posted byWpmaster
サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
Posted byWpmaster
吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
Posted byWpmaster
【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)

[org.jenkins-ci.main:jenkins-core] Arbitrary file read vulnerability in workspace browsers in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

The file browser for workspaces, archived artifacts, and $JENKINS_HOME/userContent/ follows symbolic links to locations outside the directory being browsed in Jenkins 2.274 and earlier, LTS 2.263.1 and earlier.
This allows attackers with Job/Workspace …

[org.jenkins-ci.main:jenkins-core] Arbitrary file existence check in file fingerprints in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins provides a feature for jobs to store and track fingerprints of files used during a build. Jenkins 2.274 and earlier, LTS 2.263.1 and earlier provides a REST API to check where a given fingerprint was used by which builds. This endpoint does not…

[org.jenkins-ci.main:jenkins-core] Missing permission check for paths with specific prefix in Jenkins

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins includes a static list of URLs that are always accessible even without Overall/Read permission, such as the login form. These URLs are excluded from an otherwise universal permission check.
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier doe…

[org.jenkins-ci.main:jenkins-core] Improper handling of REST API XML deserialization errors in Jenkins

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins provides XML REST APIs to configure views, jobs, and other items. When deserialization fails because of invalid data, Jenkins 2.274 and earlier, LTS 2.263.1 and earlier stores invalid object references created through these endpoints in the Old…

[Microsoft.AspNetCore.App.Runtime.linux-musl-arm] ASP.NET Core and Visual Studio Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202211/04/2022

A denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade.
References

https://nvd.nist.gov/vul…

[org.jenkins-ci.plugins:cvs] XXE vulnerability in Jenkins CVS Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/24/2022

CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows attackers able to control an agent process to have Jenkins parse a crafted changelog file that uses external entities for extraction…

[io.jenkins.plugins:chaos-monkey] Missing permission checks in Jenkins Chaos Monkey Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/24/2022

Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to generate load and to generate memory leaks.
Chaos Monkey Plugin 0.4 requires Overall/Administer perm…

[io.jenkins.plugins:chaos-monkey] Missing permission checks in Jenkins Chaos Monkey Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/17/2022

Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint.
This allows attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.
Chaos Monkey Plugin 0.4.1 requires Overall…

[org.jenkins-ci.plugins:shelve-project-plugin] CSRF vulnerability in Jenkins Shelve Project Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/17/2022

Shelve Project Plugin 3.0 and earlier does not require POST requests for HTTP endpoints, resulting in cross-site request forgery (CSRF) vulnerabilities.
These vulnerabilities allow attackers to shelve, unshelve, or delete a project.
Shelve Project Plug…

[gitaly] Gitaly Insufficient Session Expiration vulnerability

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202201/25/2023

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above. Affected versions are: >=1.79.0, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
References

https://nvd.nis…

Posts navigation

Previous Posts 1 … 81,060 81,061 81,062 81,063 81,064 … 81,119 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close