Skip to content

TechMedia

Header Image

[hammer_cli_foreman] hammer_cli_foreman Improper Certificate Validation vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202201/27/2023

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle …

[katello] katello Improper Privilege Management vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A flaw was found in Foreman’s katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the r…

[katello] katello SQL Injection vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A SQL injection flaw was found in katello’s errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix fo…

[org.jenkins-ci.plugins:jira] Jenkins Jira Plugin Incorrect Authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtain…

[org.jenkins-ci.plugins:ansible] Jenkins Ansible Plugin man in the middle vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybo…

[org.jenkins-ci.plugins:jenkins-multijob-plugin] Jenkins Multijob plugin did not check permissions in the Resume Build action

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build. Multijob plugin 1.26 introduced a permission check requiring Overall/Administer. This w…

[smalruby] smalruby and smalruby-editor vulnerable to OS Command Injection

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/13/202201/27/2023

smalruby-editor prior to 0.4.1 and smalruby prior to 0.1.11 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-2096
http://jvn.jp/en/jp/JVN50197114/index.html
http://s…

[org.jenkins-ci.plugins:groovy] Jenkins Groovy Plugin sandbox bypass vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can res…

[org.jenkins-ci.plugins:groovy] Jenkins Groovy Plugin sandbox bypass vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JV…

[mixlib-archive] mixlib-archive Path Traversal vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202201/27/2023

Chef Software’s mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using .. in tar archive entries
References

https://nvd.nist.gov/vuln/detail/CVE-2017-1000026
http…

Posts navigation

Previous Posts 1 … 81,990 81,991 81,992 81,993 81,994 … 82,021 Next Posts

Recent Posts

  • 大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
  • サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
  • 吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
  • 【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)
  • 驚き!地球!グレートネイチャー「探検!未知なる海へ~北極海・ポリネシア~」[解][字]
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`
  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定

What’s TechMedia

TechMediaはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close