Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[org.jenkins-ci.plugins:radargun] RCE vulnerability in RadarGun Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202201/14/2023

RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types. This results in a remote code execution vulnerability exploitable by users able to configure RadarGun Plugin’s build step.
RadarGun Plug…

[org.jenkins-ci.plugins:nunit] XXE vulnerability in NUnit Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202201/14/2023

NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
This allows a user able to control the input files for its post-build step to have Jenkins parse a crafted file that uses external entities fo…

[org.jenkins-ci.plugins:pipeline-githubnotify-step] Missing permission checks in Pipeline GitHub Notify Step Plugin allows capturing credentials

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202201/14/2023

A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, c…

[org.jenkins-ci.plugins:pipeline-githubnotify-step] CSRF vulnerability in Pipeline GitHub Notify Step Plugin allows capturing credentials

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202201/14/2023

A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing cred…

[org.jenkins-ci.plugins:websphere-deployer] XXE vulnerability in Jenkins WebSphere Deployer Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/20/2022

WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. This could be exploited by a user with Job/Configure permissions to upload a specially crafted war file containing a WEB-INF/ibm…

[org.jenkins-ci.main:jenkins-core] Inbound TCP Agent Protocol/3 authentication bypass in Jenkins

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/24/2022

Jenkins 2.213 and earlier, LTS 2.204.1 and earlier includes support for the Inbound TCP Agent Protocol/3 for communication between controller and agents. While this protocol has been deprecated in 2018 and was recently removed from Jenkins in 2.214, it…

[org.jenkins-ci.plugins:robot] XXE vulnerability in Jenkins Robot Framework Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/22/2022

Robot Framework Plugin 2.0.0 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
This allows a user able to control the input files for the ‘Publish Robot Framework’ post-build step to have Jenkins parse a crafte…

[org.jenkins-ci.plugins:sounds] Missing permission checks in Jenkins Sounds Plugin allow OS command execution

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/30/2022

Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins.
References

https://nvd.ni…

[org.jenkins-ci.plugins:sounds] CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/22/2022

A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2098
https://jenkins.io/s…

[org.jenkins-ci.plugins:delphix] Jenkins Delphix Plugin vulnerable to Cleartext credential storage

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/07/2022

Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-10453
https://je…

Posts navigation

Previous Posts 1 … 33 34 35 36 37 … 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close