Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[org.jenkins-ci.plugins:icescrum] Jenkins iceScrum Plugin stores credentials in Cleartext

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/07/2022

Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
References

https://nvd.nist….

[pterodactyl/panel] Pterodactyl vulnerable to 2FA Sniffing

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202201/09/2023

Pterodactyl version 0.7.13 and lower – 2FA Sniffing
Users who have enabled 2FA protections on their account can unintentionally have their account’s existence sniffed by malicious users who enter random credentials into the login fields.
Impact
Users w…

[werkzeug] Pallets Werkzeug vulnerable to Path Traversal

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202202/02/2023

In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-14322
https://palletsprojects.com/blog/werkzeug-0-15-5-released/
http://packetstorms…

[io.jenkins.docker:docker-plugin] Jenkins Docker Plugin contains Cross-Site Request Forgery

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202202/01/2023

A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs o…

[cakephp/cakephp] CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code

  • Posted inHIGH
  • Posted byWpmaster
  • 05/17/202201/14/2023

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is process…

[karteek-docsplit] Karteek Docsplit vulnerable to OS Command Injection

  • Posted inHIGH
  • Posted byWpmaster
  • 05/17/202201/27/2023

The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a PDF filename.
References

https…

[org.jenkins-ci.plugins:pollscm] Jenkins Poll SCM Plugin vulnerable to Cross-Site Request Forgery

  • Posted inHIGH
  • Posted byWpmaster
  • 05/17/202212/13/2022

Jenkins Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of projects with a known name. While Jenkins in general does not co…

[VladTheEnterprising] VladTheEnterprising allows local users to obtain sensitive information by reading MySQL root password from temporary file

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/27/2023

Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the MySQL root password from a temporary file before it is removed.
References

https://nvd.nist.gov/vuln/…

[backup_checksum] backup-agoddard and backup_checksum have Information Exposure vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/23/2023

(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by list…

[kajam] kajam allows local users to obtain sensitive information by listing the process

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/27/2023

vendor/plugins/dataset/lib/dataset/database/mysql.rb in the kajam gem 1.0.3.rc2 for Ruby places the mysql user password on the (1) mysqldump command line in the capture function and (2) mysql command line in the restore function, which allows local use…

Posts navigation

Previous Posts 1 … 34 35 36 37 38 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close