Skip to content

TechMedia

Header Image
Category

LOW

79 Posts

Featured

Posted byWpmaster
[safeurl-python] Withdrawn: safeurl-python contains Server-Side Request Forgery
Posted byWpmaster
[org.jenkins-ci.plugins:github-pr-coverage-status] Plaintext storage of Access Token in Jenkins GitHub Pull Request Coverage Status Plugin
Posted byWpmaster
[shopware/platform] Shopware’s log module vulnerable to Improper Output Neutralization
Posted byWpmaster
[rack] Denial of Service Vulnerability in Rack Content-Disposition parsing

[net.praqma:rqm-plugin] Password stored in plain text by Jenkins RQM Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 07/01/202212/13/2022

RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file net.praqma.jenkins.rqm.RqmBuilder.xml on the Jenkins controller as part of its configuration.
This password can be viewed by users with access to the Jenkins cont…

[org.jenkins-ci.plugins:nomad] Password stored in plain text by Jenkins Nomad Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/17/2022

Nomad Plugin 0.7.4 and earlier stores the passwords to authenticate against the Docker registry unencrypted in the global config.xml file on the Jenkins controller as part of its worker templates configuration.
These passwords can be viewed by users wi…

[org.jvnet.hudson.plugins:jabber] Passwords stored in plain text by Jenkins Jabber (XMPP) notifier and control Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/16/2022

Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file hudson.plugins.jabber.im.transport.JabberPublisher.xml on the Jenkins controller as part of its configuration.
These passwords can …

[org.jenkins-ci.plugins:cloud-stats] Missing permission check in Jenkins Cloud Statistics Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/16/2022

Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.
Cloud Stati…

[org.jenkins-ci.plugins:build-with-parameters] CSRF vulnerability in Jenkins Build With Parameters Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/23/2022

Build With Parameters Plugin 1.5 and earlier does not require POST requests for its form submission endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to build a project with attacker-specified…

[org.jenkins-ci.plugins:bumblebee] Credentials stored in plain text by Jenkins Bumblebee HP ALM Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/21/2022

Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file com.agiletestware.bumblebee.BumblebeeGlobalConfig.xml on the Jenkins controller as part of its configuration.
These credentials can be viewed by u…

[org.jenkins-ci.main:jenkins-core] Missing permission check for paths with specific prefix in Jenkins

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins includes a static list of URLs that are always accessible even without Overall/Read permission, such as the login form. These URLs are excluded from an otherwise universal permission check.
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier doe…

[gitaly] Gitaly Insufficient Session Expiration vulnerability

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202201/25/2023

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above. Affected versions are: >=1.79.0, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.
References

https://nvd.nis…

[org.jenkins-ci.plugins:labmanager] Password stored in plain text by Jenkins VMware Lab Manager Slaves Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/22/2022

Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
References

https://nvd…

[com.rapid7:jenkinsci-appspider-plugin] Password stored in plain text by Jenkins AppSpider Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/22/2022

AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file com.rapid7.jenkinspider.PostBuildScan.xml on the Jenkins controller as part of its configuration.
This password can be viewed by users with access to the…

Posts navigation

Previous Posts 1 2 3 4 5 6 … 8 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close