Skip to content

Underground News

Header Image

[org.jenkins-ci.main:jenkins-core] OS Command Injection in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/02/2022

Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called ‘Launch agent via execution of command on master’. This allowed them to run arbitrary shell commands on t…

[org.apache.tomcat:tomcat] Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/14/202207/01/2022

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL…

Google Workspace Updates Weekly Recap – May 13, 2022

  • Posted inAdmin consoleAPIGoogle CalendarGoogle ChatGoogle DriveGoogle MeetGoogle SitesIdentityOtherSecurity and Compliance
  • Posted byUnknown
  • 05/14/202205/14/2022

New updates Unless otherwise indicated, the features below are fully launched or in the process of rolling out (rollouts should take no more than 15 business days to complete), launching to both Rapid and Scheduled Release at the same time (if not…

Metaの次世代ヘッドセット、実機が初公開。マーク・ザッカーバーグ氏が自ら実演

  • Posted inUncategorized
  • Posted byPHILE WEB
  • 05/13/2022

Metaのマーク・ザッカーバーグCEOは、新型のハイエンドMR(複合現実)ヘッドセット「Projec…

[npm] Incorrect Permission Assignment for Critical Resource in NPM

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/29/2022

An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as “next: 5.7.0” and therefore automatically installed by an “npm upgrade -g npm” command, and also announced in the vendor’s blog without mention of pre-release status). It might a…

[mysql:mysql-connector-java] Improper Privilege Management in MySQL Connectors Java

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/29/2022

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple pro…

[org.jenkins-ci.main:jenkins-core] Missing Release of Resource after Effective Lifetime in Jenkins

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/29/2022

A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in…

[passenger] Phusion Passenger incorrect permission assignment

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202206/18/2022

An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are …

[com.amazonaws:codedeploy] AWS CodeDeploy Plugin stored AWS Secret Key in plain text

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/28/2022

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack appears to be exploitable via loc…

[org.springframework.webflow:spring-webflow] Insecure Default Initialization of Resource in Pivotal Spring Web Flow

  • Posted inUncategorized
  • Posted byGitHub
  • 05/13/202207/01/2022

An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to ‘false’) can be vulnerable to malicious EL exp…

Posts navigation

Previous Posts 1 … 81,135 81,136 81,137 81,138 81,139 … 81,225 Next Posts

Recent Posts

  • カローラ セリカ マークII… 新型クラウンもビックリ!? 超名門トヨタがビッグネームで起こした「大変革」6選 – 自動車情報誌「ベストカー」
  • 5歳~17歳の新型コロナワクチン「接種を推奨」日本小児科学会 | NHK
  • ホラーゲーム『野狗子: Slitterhead』を開発中の外山圭一郎氏・佐藤一信氏とSIEインディーズイニシアチブ代表の吉田修平氏による対談映像が公開。
  • 花粉症に救世主? “エリート秋田杉”とは | NHK | ビジネス特集
  • 韓鶴子「女帝の正体」 13歳で文鮮明に見初められ4回帝王切開 14人出産 | 週刊文春 電子版
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close