Skip to content

TechMedia

Header Image

[org.jenkins-ci.plugins:hp-application-automation-tools-plugin] CSRF vulnerability in Jenkins Micro Focus Application Automation Tools Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

Micro Focus Application Automation Tools Plugin 6.7 and earlier does not perform permission checks in methods implementing form validation.
This allows attackers with Overall/Read permission to connect to attacker-specified URLs using attacker-specifie…

[org.jenkins-ci.main:jenkins-core] View name validation bypass in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name. When a form to create a view is submitted, the name is included twice in the submission. One instance is validated, but the other …

[org.jenkins-ci.plugins:promoted-builds] CSRF vulnerability in Jenkins promoted builds Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

promoted builds Plugin 3.9 and earlier does not require POST requests for HTTP endpoints implementing promotion (regular, forced, and re-execute), resulting in cross-site request forgery (CSRF) vulnerabilities.
These vulnerabilities allow attackers to …

[org.jenkins-ci.main:jenkins-core] Improper Input Validation in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the config.xml REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with…

[org.jvnet.hudson.plugins:jabber] Passwords stored in plain text by Jenkins Jabber (XMPP) notifier and control Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/16/2022

Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file hudson.plugins.jabber.im.transport.JabberPublisher.xml on the Jenkins controller as part of its configuration.
These passwords can …

[org.jenkins-ci.plugins:dependency-track] Missing permission checks in Jenkins OWASP Dependency-Track Plugin allow capturing credentials

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/16/2022

OWASP Dependency-Track Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained t…

[org.jenkins-ci.plugins:tfs] Missing permission check in Jenkins Team Foundation Server Plugin allows enumerating credentials IDs

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/16/2022

Team Foundation Server Plugin 5.157.1 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an…

[org.jenkins-ci.plugins:tfs] CSRF vulnerability in Jenkins Team Foundation Server Plugin allow capturing credentials

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/16/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing …

[org.jenkins-ci.plugins:dependency-track] CSRF vulnerability and in Jenkins OWASP Dependency-Track Plugin allow capturing credentials

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/16/2022

OWASP Dependency-Track Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained t…

[io.jenkins.plugins:rest-list-parameter] Stored XSS vulnerability in Jenkins REST List Parameter Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/16/2022

REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
REST List Paramete…

Posts navigation

Previous Posts 1 … 81,073 81,074 81,075 81,076 81,077 … 81,135 Next Posts

Recent Posts

  • 大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
  • サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
  • 吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
  • 【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)
  • 驚き!地球!グレートネイチャー「探検!未知なる海へ~北極海・ポリネシア~」[解][字]
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`
  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定

What’s TechMedia

TechMediaはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close