Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[org.jenkins-ci.plugins:pipeline-maven] Missing permission check in Jenkins Pipeline Maven Integration Plugin allows enumerating credentials IDs

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

Pipeline Maven Integration Plugin 3.8.2 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read access to Jenkins to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as p…

[org.jenkins-ci.plugins:fortify-on-demand-uploader] CSRF vulnerability in Jenkins Fortify on Demand Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.
This form validation method req…

[org.jenkins-ci.plugins:sonargraph-integration] Stored XSS vulnerability in Jenkins Sonargraph Integration Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation.
This results in a stored cross-site scripting (XSS) vulnerability that can be exploited by users with Job/Configure permission.
Sonarg…

[org.jenkins-ci.plugins:fortify-on-demand-uploader] Users with Overall/Read access could enumerate credentials IDs in Jenkins Fortify on Demand Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/29/2022

Fortify on Demand Plugin provides a list of applicable credentials IDs to allow users configuring the plugin to select the one to use.
This functionality does not correctly check permissions in Fortify on Demand Plugin 6.0.0 and earlier, allowing any u…

[hudson.plugins:project-inheritance] Missing permission check in Jenkins Project Inheritance Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/22/2022

Jenkins Project Inheritance Plugin 21.04.03 and earlier does not redact encrypted secrets in the ‘getConfigAsXML’ API URL when transmitting job config.xml data to users without Job/Configure.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2198
h…

[org.jenkins-ci.plugins:svn-partial-release-mgr] XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/22/2022

Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation.
This results in a reflected cross-site scripting (XSS) vulnerability that can also be exploited similar to a sto…

[hudson.plugins:project-inheritance] Missing permission check in Jenkins Project Inheritance Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/22/2022

Jenkins limits access to job configuration XML data (config.xml) to users with Job/ExtendedRead permission, typically implied by Job/Configure permission. Project Inheritance Plugin has several job inspection features, including the API URL /job/…​/get…

[org.jenkins-ci.plugins:swarm] CSRF vulnerability in Jenkins Swarm Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

Swarm Plugin adds API endpoints to add or remove agent labels. In Swarm Plugin 3.20 and earlier these only require a global Swarm secret to use, and no regular permission check is performed. This allows users with Agent/Create permission to add or remo…

[io.jenkins.plugins:echarts-api] Stored XSS vulnerability in Jenkins ECharts API Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts.
This results in a stored cross-site scripting (XSS) vulnerability that can be exploited by users with Job/Configure permission.
ECharts API Plugin 4.7.0…

[org.jenkins-ci.plugins:swarm] Improper permission checks in Jenkins Swarm Plugin

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/25/202212/21/2022

Swarm Plugin adds API endpoints to add or remove agent labels. In Swarm Plugin 3.20 and earlier these only require a global Swarm secret to use, and no regular permission check is performed. This allows users with Agent/Create permission to add or remo…

Posts navigation

Previous Posts 1 … 44 45 46 47 48 … 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close