Skip to content

TechMedia

Header Image

[katello] katello Improper Privilege Management vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A flaw was found in Foreman’s katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the r…

[katello] katello SQL Injection vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A SQL injection flaw was found in katello’s errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix fo…

[org.jenkins-ci.plugins:jira] Jenkins Jira Plugin Incorrect Authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtain…

[org.jenkins-ci.plugins:ansible] Jenkins Ansible Plugin man in the middle vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybo…

[org.jenkins-ci.plugins:jenkins-multijob-plugin] Jenkins Multijob plugin did not check permissions in the Resume Build action

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build. Multijob plugin 1.26 introduced a permission check requiring Overall/Administer. This w…

[smalruby] smalruby and smalruby-editor vulnerable to OS Command Injection

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/13/202201/27/2023

smalruby-editor prior to 0.4.1 and smalruby prior to 0.1.11 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-2096
http://jvn.jp/en/jp/JVN50197114/index.html
http://s…

[org.jenkins-ci.plugins:groovy] Jenkins Groovy Plugin sandbox bypass vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can res…

[org.jenkins-ci.plugins:groovy] Jenkins Groovy Plugin sandbox bypass vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JV…

[mixlib-archive] mixlib-archive Path Traversal vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202201/27/2023

Chef Software’s mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using .. in tar archive entries
References

https://nvd.nist.gov/vuln/detail/CVE-2017-1000026
http…

[fluentd] Fluentd Escape Sequence Injection Vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/13/202201/25/2023

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

Posts navigation

Previous Posts 1 … 81,104 81,105 81,106 81,107 81,108 … 81,135 Next Posts

Recent Posts

  • 大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
  • サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
  • 吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
  • 【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)
  • 驚き!地球!グレートネイチャー「探検!未知なる海へ~北極海・ポリネシア~」[解][字]
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`
  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定

What’s TechMedia

TechMediaはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close