Skip to content

TechMedia

Header Image

[org.jenkins-ci.plugins:meliora-testlab] Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key

  • Posted inLOW
  • Posted byWpmaster
  • 05/14/202212/13/2022

An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows attackers with file system access to the Jenkins master to obtain the API key stored in this plugin’s confi…

[org.jenkins-ci.plugins:collabnet] Jenkins CollabNet Plugin man in the middle vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to. CollabNet Plugin 2.0…

[fat_free_crm] Fat Free CRM Cross-Site Request Forgery vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/24/2023

Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account.
References

https://n…

[cakephp/cakephp] CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/14/2023

CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
References

https://nvd.nist.gov/vuln/detail/CVE-2015-8379
https://github.com/cakephp/cakephp/commit/0f818a23a876c01429196b…

[org.jenkins-ci.plugins:resource-disposer] Jenkins Resource Disposer Plugin allows attacker to stop tracking specified resource

  • Posted inLOW
  • Posted byWpmaster
  • 05/14/202212/13/2022

A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a specified resource. Additionally, this API endpoint did not require POST requests, resu…

[spree] Spree allows remote attackers to obtain sensitive information

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/produc…

[org.jenkins-ci.plugins:publish-over-cifs] Jenkins Publisher Over CIFS Plugin confused deputy vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A confused deputy vulnerability exists in Jenkins Publisher Over CIFS Plugin 0.10 and earlier in CifsPublisherPluginDescriptor.java that allows attackers to have Jenkins connect to an attacker specified CIFS server with attacker specified credentials. …

[cakephp/cakephp] CakePHP allows remote attackers to spoof their IP

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/14/2023

The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-4793
https://bakery.cakephp.org/2016/03/13/cakephp_2613_2711_282_3017_3112…

[org.jenkins-ci.plugins:saltstack] Jenkins SaltStack Plugin allows attackers to capture credentials with a known credentials ID stored in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java. SaltStack Plugin did not perform permission checks on methods implementing form validation. This allowed u…

[curl] curl FTP path confusion leads to NIL byte out of bounds write

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/14/202203/02/2023

curl can be coerced into writing a zero byte out of bounds.
This bug can trigger when curl is told to work on an FTP URL, with the setting to only issue a single CWD command (–ftp-method singlecwd or the libcurl alternative CURLOPT_FTP_FILEMETHOD).
cu…

Posts navigation

Previous Posts 1 … 81,988 81,989 81,990 81,991 81,992 … 82,021 Next Posts

Recent Posts

  • 大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
  • サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
  • 吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
  • 【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)
  • 驚き!地球!グレートネイチャー「探検!未知なる海へ~北極海・ポリネシア~」[解][字]
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`
  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定

What’s TechMedia

TechMediaはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close