Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[io.jenkins.blueocean:blueocean] Missing permission check in Blue Ocean Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

Updated 2020-09-16
This entry previously misidentified the problematic behavior. The HTTP request itself is legitimate, but only authorized users should be able to perform it.
Original Description
Blue Ocean Plugin 1.23.2 and earlier does not perform p…

[org.jenkins-ci.plugins:cloudbees-jenkins-advisor] Incorrect permission check in Health Advisor by CloudBees Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to view an administrative configuration page.
Health Advisor by CloudBees Plugin …

[org.jenkins-ci.plugins:email-ext] Missing hostname validation in Email Extension Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured SMTP server. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.
Email Extension Plugin …

[io.jenkins.blueocean:blueocean] Path traversal vulnerability in Blue Ocean Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag, blueocean.features.GIT_READ_SAVE_TYPE, that when set to the value clone allows an attacker with Item/Configure or Item/Create permission to read arbitrary files on the Jenkins …

[org.jenkins-ci.plugins:soapui-pro-functional-testing] Passwords stored in plain text by Jenkins ReadyAPI Functional Testing Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

ReadyAPI Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files as part of its configuration. These project passwords can be viewed by attackers with Extended Read permission or access to the Jenkins cont…

[org.jenkins-ci.plugins:soapui-pro-functional-testing] Passwords transmitted in plain text by Jenkins ReadyAPI Functional Testing Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

ReadyAPI Functional Testing Plugin stores project passwords in job config.xml files on the Jenkins controller as part of its configuration.
While these passwords are stored encrypted on disk since ReadyAPI Functional Testing Plugin 1.4, they are transm…

[org.jenkins-ci.plugins:database] CSRF vulnerability in Jenkins Database Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified database server using attacker-specified credentials.
Database Plugin 1.7 requires POST requests for the a…

[org.jenkins-ci.plugins:database] Missing permission checks in Jenkins Database Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.
Database Plugin 1.7 requires Overall/Ad…

[org.jenkins-ci.plugins:flaky-test-handler] CSRF vulnerability in Jenkins Flaky Test Handler Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

Flaky Test Handler Plugin 1.0.4 and earlier does not require POST requests for the “Deflake this build” feature, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to rebuild a project at a previous git …

[org.jenkins-ci.main:jenkins-core] Improper Neutralization of Input During Web Page Generation in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202202/01/2023

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via ‘Trigger builds remotely’, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure per…

Posts navigation

Previous Posts 1 … 43 44 45 46 47 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close