Skip to content

TechMedia

Header Image

[org.jenkins-ci.plugins:pollscm] Jenkins Poll SCM Plugin vulnerable to Cross-Site Request Forgery

  • Posted inHIGH
  • Posted byWpmaster
  • 05/17/202212/13/2022

Jenkins Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of projects with a known name. While Jenkins in general does not co…

[org.jenkins-ci.plugins:docker-commons] Jenkins Docker Commons Plugin allows any user with Overall/Read permission to get list of valid credentials IDs

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/17/202212/13/2022

Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they’d like to use to authenticate with a Docker Registry. This functionality did not check permissions, allowing any user with Overal…

[org.jenkins-ci.plugins:github-branch-source] Jenkins GitHub Branch Source Plugin vulnerable to Cross-Site Request Forgery

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/17/202212/13/2022

GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any us…

[ccsv] ccsv Double Free vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/17/202201/27/2023

The foreach function in ext/ccsv.c in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact via a crafted file.
References

https://nvd.nist.gov/vuln/detail/CVE-201…

[org.jenkins-ci.plugins:github-branch-source] Jenkins GitHub Branch Source Plugin allows any user with Overall/Read permission to get list of valid credentials IDs

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/17/202212/13/2022

GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they’d like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid…

[org.jenkins-ci.plugins:subversion] Jenkins Subversion Plugin Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/17/202212/13/2022

Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Item/Configure) …

[org.richfaces:richfaces] JBoss RichFaces Improper Input Validation vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/17/202212/13/2022

The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.
…

バットマン亡き後のゴッサム・シティを描く「ゴッサム・ナイツ」が2022年10月25日(火)に発売決定!

  • Posted inUncategorized
  • Posted byWpmaster
  • 05/14/2022

ゴッサム・シティを舞台にした新作オープンワールドアクションRPG「ゴッサム・ナイツ」当初は2021年…

[VladTheEnterprising] VladTheEnterprising allows local users to write to arbitrary files via a symlink attack

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-4996
https://exchange.xforce.ibmc…

[VladTheEnterprising] VladTheEnterprising allows local users to obtain sensitive information by reading MySQL root password from temporary file

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/27/2023

Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the MySQL root password from a temporary file before it is removed.
References

https://nvd.nist.gov/vuln/…

Posts navigation

Previous Posts 1 … 81,099 81,100 81,101 81,102 81,103 … 81,135 Next Posts

Recent Posts

  • 大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
  • サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
  • 吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
  • 【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)
  • 驚き!地球!グレートネイチャー「探検!未知なる海へ~北極海・ポリネシア~」[解][字]
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`
  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定

What’s TechMedia

TechMediaはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close