Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[point-cli] point-cli allows local users to obtain sensitive information by listing the process

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/27/2023

lib/commands/setup.rb in the point-cli gem 0.0.1 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-4997
http://ww…

[lean-ruport] lean-ruport allows local users to obtain sensitive information by listing the process

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/27/2023

test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[cakephp/cakephp] CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/14/2023

CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
References

https://nvd.nist.gov/vuln/detail/CVE-2015-8379
https://github.com/cakephp/cakephp/commit/0f818a23a876c01429196b…

[cakephp/cakephp] CakePHP allows remote attackers to spoof their IP

  • Posted inHIGH
  • Posted byWpmaster
  • 05/14/202201/14/2023

The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-4793
https://bakery.cakephp.org/2016/03/13/cakephp_2613_2711_282_3017_3112…

[asciidoctor] Asciidoctor Infinite Loop vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202201/25/2023

Asciidoctor in versions < 1.5.8 allows remote attackers to cause a denial of service (infinite loop). The loop was caused by the fact that Parser.next_block was not exhausting all the lines in the reader as the while loop expected it would. This was…

[org.jenkins-ci.plugins:build-publisher] Jenkins Build-Publisher plugin has Insufficiently Protected Credentials

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowin…

[hammer_cli_foreman] hammer_cli_foreman Improper Certificate Validation vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202201/27/2023

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle …

[org.jenkins-ci.plugins:groovy] Jenkins Groovy Plugin sandbox bypass vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can res…

[org.jenkins-ci.plugins:groovy] Jenkins Groovy Plugin sandbox bypass vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202212/07/2022

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JV…

[mixlib-archive] mixlib-archive Path Traversal vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/13/202201/27/2023

Chef Software’s mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using .. in tar archive entries
References

https://nvd.nist.gov/vuln/detail/CVE-2017-1000026
http…

Posts navigation

Previous Posts 1 … 35 36 37 38 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close