Skip to content

TechMedia

Header Image
Author

wpmaster

811184 Posts

Featured

Posted byWpmaster
大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
Posted byWpmaster
サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
Posted byWpmaster
吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
Posted byWpmaster
【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)

[org.jenkins-ci.plugins:build-publisher] Jenkins Build-Publisher plugin has Insufficiently Protected Credentials

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowin…

[org.jenkins-ci.plugins:parameterized-trigger] Parameterized Trigger Plugin fails to check Item/Build permission

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins. The plugin has been adapted to now check f…

[hammer_cli_foreman] hammer_cli_foreman Improper Certificate Validation vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202201/27/2023

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle …

[katello] katello Improper Privilege Management vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A flaw was found in Foreman’s katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the r…

[katello] katello SQL Injection vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A SQL injection flaw was found in katello’s errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix fo…

[org.jenkins-ci.plugins:jira] Jenkins Jira Plugin Incorrect Authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtain…

[org.jenkins-ci.plugins:ansible] Jenkins Ansible Plugin man in the middle vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybo…

[org.jenkins-ci.plugins:jenkins-multijob-plugin] Jenkins Multijob plugin did not check permissions in the Resume Build action

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build. Multijob plugin 1.26 introduced a permission check requiring Overall/Administer. This w…

[smalruby] smalruby and smalruby-editor vulnerable to OS Command Injection

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/13/202201/27/2023

smalruby-editor prior to 0.4.1 and smalruby prior to 0.1.11 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-2096
http://jvn.jp/en/jp/JVN50197114/index.html
http://s…

[org.jenkins-ci.plugins:groovy] Jenkins Groovy Plugin sandbox bypass vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can res…

Posts navigation

Previous Posts 1 … 81,088 81,089 81,090 81,091 81,092 … 81,119 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close