Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[org.csanchez.jenkins.plugins:kubernetes] Missing Authorization in Jenkins Kubernetes Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2308
https://www.jenkins.io/security/advis…

[org.jenkins-ci.plugins:mercurial] Missing Authorization in Jenkins Mercurial Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2306
https://ww…

[org.jenkins-ci.plugins:mercurial] Improper Restriction of XML External Entity Reference in Jenkins Mercurial Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2305
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2115
http…

[org.csanchez.jenkins.plugins:kubernetes] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2307
https://www.jenkins.io/security/advisory/2020-11-0…

[org.wildfly:wildfly-dist] Uncontrolled Resource Consumption in WildFly

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an…

[hermes-engine] Out-of-bounds Read in Facebook Hermes

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/28/2022

An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that…

[hermes-engine] Always-Incorrect Control Flow Implementation in Facebook Hermes

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/28/2022

A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7fdddfc allows attackers to potentially read out of bounds or theoretically execute arbitrary code via crafted Jav…

[org.jenkins-ci.plugins:script-security] Protection Mechanism Failure in Jenkins Script Security Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide crafted return values or script binding content that can result in arbitrary code execution on the…

[org.jenkins-ci.plugins:mailer] Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin

  • Posted inUncategorized
  • Posted byGitHub
  • 05/25/202206/24/2022

Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-2252
https://www.jenkins.io/security/advisory/2020-09-16/#SECURITY-1813
htt…

[Microsoft.AspNetCore.Owin] Cookie parsing failure

  • Posted inseverity
  • Posted byGitHub
  • 05/25/202208/04/2022

A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being …

Posts navigation

Previous Posts 1 … 51 52 53 54 55 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close