Skip to content

TechMedia

Header Image

[org.jenkins-ci.tools:git-parameter] Stored XSS vulnerability in Jenkins Git Parameter Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/21/2022

Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the ‘Build with Parameters’ page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Git Paramet…

[org.jenkins-ci.plugins:Parameterized-Remote-Trigger] Secret stored in plain text by Jenkins Parameterized Remote Trigger Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/21/2022

Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file org.jenkinsci.plugins.ParameterizedRemoteTrigger.RemoteBuildConfiguration.xml on the Jenkins controller as part of its configuration. Thi…

[org.jenkins-ci.plugins:database] CSRF vulnerability in Jenkins Database Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/21/2022

Database Plugin 1.6 and earlier does not require POST requests for the database console, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to execute arbitrary SQL scripts.
Database Plugin 1.7 removes t…

[org.jenkins-ci.plugins:database] CSRF vulnerability in Jenkins Database Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified database server using attacker-specified credentials.
Database Plugin 1.7 requires POST requests for the a…

[org.jenkins-ci.plugins:database] Missing permission checks in Jenkins Database Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.
Database Plugin 1.7 requires Overall/Ad…

[org.jenkins-ci.plugins:tfs] Credentials stored in plain text by Jenkins tfs Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/21/2022

tfs Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file hudson.plugins.tfs.TeamPluginGlobalConfig.xml on the Jenkins controller as part of its configuration. This secret can be viewed by attackers with access…

[org.jenkins-ci.plugins:valgrind] XXE vulnerability in Jenkins Valgrind Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/21/2022

Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
This allows a user able to control the input files for the Valgrind plugin parser to have Jenkins parse a crafted file that uses external e…

[linux-cmdline] linux-cmdline is vulnerable to Prototype Pollution via the constructor

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/25/202212/06/2022

The package linux-cmdline is a parser for Linux kernel command line arguments. Versions before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-7704
https://github.com/piranna/linux-…

[org.jenkins-ci.plugins:flaky-test-handler] CSRF vulnerability in Jenkins Flaky Test Handler Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

Flaky Test Handler Plugin 1.0.4 and earlier does not require POST requests for the “Deflake this build” feature, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to rebuild a project at a previous git …

[org.jenkins-ci.plugins:pipeline-maven] CSRF vulnerability in Jenkins Pipeline Maven Integration Plugin allow capturing credentials

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/21/2022

Pipeline Maven Integration Plugin 3.8.2 and earlier does not perform a permission check in a method implementing form validation.
This allows users with Overall/Read access to Jenkins to connect to an attacker-specified JDBC URL using attacker-specifie…

Posts navigation

Previous Posts 1 … 81,969 81,970 81,971 81,972 81,973 … 82,021 Next Posts

Recent Posts

  • 大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
  • サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
  • 吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
  • 【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)
  • 驚き!地球!グレートネイチャー「探検!未知なる海へ~北極海・ポリネシア~」[解][字]
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`
  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定

What’s TechMedia

TechMediaはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close