Skip to content

TechMedia

Header Image
Category

LOW

79 Posts

Featured

Posted byWpmaster
[safeurl-python] Withdrawn: safeurl-python contains Server-Side Request Forgery
Posted byWpmaster
[org.jenkins-ci.plugins:github-pr-coverage-status] Plaintext storage of Access Token in Jenkins GitHub Pull Request Coverage Status Plugin
Posted byWpmaster
[shopware/platform] Shopware’s log module vulnerable to Improper Output Neutralization
Posted byWpmaster
[rack] Denial of Service Vulnerability in Rack Content-Disposition parsing

[com.hoiio.jenkins:sms] Access token stored in plain text by Jenkins SMS Notification Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/22/2022

SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file com.hoiio.jenkins.plugin.SMSNotification.xml on the Jenkins controller as part of its configuration.
This access token can be viewed by users wi…

[org.jenkins-ci.plugins:couchdb-statistics] Password stored in plain text by Jenkins couchdb-statistics Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/22/2022

couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file org.jenkinsci.plugins.couchstats.CouchStatsConfig.xml on the Jenkins controller as part of its configuration.
This password can be viewed …

[org.jenkins-ci.plugins:elastest] Passwords stored in plain text by ElasTest Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202201/05/2023

Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
References

https://nvd.nist….

[org.jenkins-ci.plugins:tfs] Credentials stored in plain text by Jenkins tfs Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/21/2022

tfs Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file hudson.plugins.tfs.TeamPluginGlobalConfig.xml on the Jenkins controller as part of its configuration. This secret can be viewed by attackers with access…

[org.jenkins-ci.plugins:Parameterized-Remote-Trigger] Secret stored in plain text by Jenkins Parameterized Remote Trigger Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/21/2022

Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file org.jenkinsci.plugins.ParameterizedRemoteTrigger.RemoteBuildConfiguration.xml on the Jenkins controller as part of its configuration. Thi…

[org.jenkins-ci.plugins:email-ext] Jenkins Email Extension Plugin SMTP password transmitted and displayed in plain text

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/21/2022

Email Extension Plugin stores an SMTP password in its global configuration file hudson.plugins.emailext.ExtendedEmailPublisher.xml on the Jenkins controller as part of its configuration.
While this password is stored encrypted on disk, it is transmitte…

[org.jenkins-ci.plugins:ec2] CSRF vulnerability in Amazon EC2 Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/17/2022

Amazon EC2 Plugin 1.50.1 and earlier does not require POST requests in several HTTP endpoints, resulting in cross-site request forgery (CSRF) vulnerabilities. This allows an attacker to provision instances with an attacker-specified template ID.
Amazon…

[org.jenkins-ci.plugins:credentials-binding] Improper masking of some secrets in Jenkins Credentials Binding Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/17/2022

Credentials Binding Plugin allows specifying passwords and other secrets as environment variables, and will hide them from console output in builds. As a side effect of the fix for SECURITY-698, $ characters in secrets are escaped to $$. This will then…

[org.jenkins-ci.plugins:artifactory] Passwords transmitted in plain text by Jenkins Artifactory Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/22/2022

Jenkins Artifactory Plugin 3.6.0 and earlier stores Artifactory server passwords in its global configuration file org.jfrog.hudson.ArtifactoryBuilder.xml on the Jenkins controller as part of its configuration.
While the password is stored encrypted on …

[org.jenkins-ci.plugins:artifactory] Passwords stored in plain text by Jenkins Artifactory Plugin

  • Posted inLOW
  • Posted byWpmaster
  • 05/25/202212/22/2022

Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password in plain text in the global configuration file org.jfrog.hudson.ArtifactoryBuilder.xml. This password can be viewed by users with access to the Jenkins controller file system.
…

Posts navigation

Previous Posts 1 … 3 4 5 6 7 8 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close