Skip to content

TechMedia

Header Image
Category

MODERATE

588 Posts

Featured

Posted byWpmaster
[vitess.io/vitess] vitess allows users to create keyspaces that can deny access to already existing keyspaces
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to account takeover because password reset links do not expire
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control
Posted byWpmaster
[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

[spree] Spree allows remote attackers to obtain sensitive information

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/produc…

[org.jenkins-ci.plugins:publish-over-cifs] Jenkins Publisher Over CIFS Plugin confused deputy vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

A confused deputy vulnerability exists in Jenkins Publisher Over CIFS Plugin 0.10 and earlier in CifsPublisherPluginDescriptor.java that allows attackers to have Jenkins connect to an attacker specified CIFS server with attacker specified credentials. …

[org.jenkins-ci.plugins:saltstack] Jenkins SaltStack Plugin allows attackers to capture credentials with a known credentials ID stored in Jenkins

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202212/13/2022

An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java. SaltStack Plugin did not perform permission checks on methods implementing form validation. This allowed u…

[authlogic] Authlogic Information Exposure vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/14/202201/27/2023

The Authlogic gem for Ruby on Rails prior to version 3.3.0 makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known sec…

[org.jenkins-ci.plugins:vsphere-cloud] Jenkins vSphere Plugin incorrect authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/08/2022

An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSp…

[org.jenkins-ci.plugins:subversion] Jenkins Subversion Plugin Incorrect Authorization vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/08/2022

An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and users. As of v…

[org.jenkins-ci.plugins:google-play-android-publisher] Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/08/2022

An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs. As of version 1.7, enumeration of credentials …

[org.jenkins-ci.plugins:parameterized-trigger] Parameterized Trigger Plugin fails to check Item/Build permission

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202212/07/2022

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins. The plugin has been adapted to now check f…

[katello] katello Improper Privilege Management vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A flaw was found in Foreman’s katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the r…

[katello] katello SQL Injection vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 05/13/202201/27/2023

A SQL injection flaw was found in katello’s errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix fo…

Posts navigation

Previous Posts 1 … 54 55 56 57 58 59 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close