Skip to content

Underground News

Header Image
Author

GitHub

925 Posts

Featured

Posted byGitHub
[github.com/sigstore/cosign] cosign’s `cosign verify-attestaton –type` can report a false positive if any attestation exists
Posted byGitHub
[github.com/sigstore/policy-controller] PolicyController before 0.2.1 may bypass attestation verification
Posted byGitHub
[nbconvert] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Posted byGitHub
[owning_ref] owning_ref vulnerable to multiple soundness issues

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/29/2022

A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of…

[org.jenkins-ci.main:jenkins-core] Deserialization of Untrusted Data in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/29/2022

A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-…

[org.jenkins-ci.main:jenkins-core] Improper Authentication in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/29/2022

A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.
R…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202206/29/2022

A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.
References

https://nvd.nist.gov/…

[org.jenkins-ci.main:jenkins-core] Improper Input Validation in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/02/2022

The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets…

[org.jenkins-ci.main:jenkins-core] Improper Certificate Validation in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/02/2022

Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/02/2022

The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no…

[org.jenkins-ci.main:jenkins-core] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/02/2022

Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote API. This included e.g. Jenkins users’ email addresse…

[org.jenkins-ci.main:jenkins-core] OS Command Injection in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/02/2022

Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called ‘Launch agent via execution of command on master’. This allowed them to run arbitrary shell commands on t…

[org.jenkins-ci.main:jenkins-core] Improper Neutralization of Input During Web Page Generation in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/02/2022

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metachara…

Posts navigation

Previous Posts 1 … 67 68 69 70 71 … 93 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close