Skip to content

TechMedia

Header Image

[org.jenkins-ci.plugins:google-login] Jenkins Google Login Plugin Open Redirect vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login. Google Login Plugin 1.3.1 only performs redirects t…

[org.jenkins-ci.plugins:google-login] Jenkins Google Login Plugin Session Fixation vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session. Google Login Plug…

[org.jenkins-ci.plugins:htmlpublisher] Jenkins HTML Publisher Plugin path traversal vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master. In version 1.16, …

[org.jenkins-ci.plugins:github-branch-source] Jenkins GitHub Branch Source Plugin vulnerable to Server-Side Request Forgery

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL. Additionally, this form…

[org.jenkins-ci.plugin:ghprb] Jenkins GitHub Pull Request Builder Plugin credential capture vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specif…

[org.jenkins-ci.plugins:cas-plugin] Jenkins CAS Plugin Server-Side Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL. Additionally, this form validati…

[ember-source] Ember.js Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose cont…

[org.jenkins-ci.plugins:saml] Jenkins SAML Plugin Session Fixation vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session. SAML Plugin 1.0.7 invalidates…

[org.jenkins-ci.plugins:badge] Jenkins Badge Plugin cross-site scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in anot…

[xapian-core] xapian-core Cross-site Scripting vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
References

https://nvd.nist.gov/vuln/detail/CVE-2018-0499
https://lists…

Posts navigation

Previous Posts 1 … 81,987 81,988 81,989 81,990 81,991 … 82,021 Next Posts

Recent Posts

  • 大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
  • サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
  • 吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
  • 【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)
  • 驚き!地球!グレートネイチャー「探検!未知なる海へ~北極海・ポリネシア~」[解][字]
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`
  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定

What’s TechMedia

TechMediaはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close