Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[org.jenkins-ci.plugins:nested-view] Cross-site Scripting in Jenkins Nested View Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202207/06/2022

Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-34182
https://www.jenkins.io/secur…

[org.lilicurroad.jenkins:packageversion] Cross-site Scripting in Jenkins Package Version Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202207/06/2022

Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permissi…

[org.jenkins-ci.plugins:hidden-parameter] Cross-site Scripting in Jenkins Hidden Parameter Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202207/06/2022

Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/…

[org.jenkins-ci.plugins:embeddable-build-status] Missing Authorization in Jenkins Embeddable Build Status Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202207/06/2022

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for “unprotected” status badge access, allowing attackers without any permissions to obtain the build s…

[com.jfinal:jfinal] Cross-site Scripting in Jfinal CMS

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202206/25/2022

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-33113
https://github.com/jflyfox…

[diffy] Improper handling of double quotes in file name in Diffy in Windows environment

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202207/14/2022

The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string.
References

http…

[me.leejay.jenkins:date-parameter] Cross-site Scripting in Jenkins Date Parameter Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202207/06/2022

Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure perm…

[aiohttp] Withdrawn: Denial of Service in aiohttp

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202206/29/2022

Withdrawn
This advisory has been withdrawn because the maintainers of aiohttp and multiple third parties disputed the validity of the issue. There is not sufficient evidence for the claims in the original report.
Original Description
aiohttp v3.8.1 was…

[io.jenkins.plugins:agent-server-parameter] Cross-site Scripting in Jenkins Agent Server Parameter Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202207/06/2022

Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/…

[com.moded.extendedchoiceparameter:dynamic_extended_choice_parameter] Cross-site Scripting in Jenkins Dynamic Extended Choice Parameter Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 06/24/202207/06/2022

Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable b…

Posts navigation

Previous Posts 1 … 27 28 29 30 31 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close