OX App Suite through 7.10.6 allows XSS by forcing block-wise read.Read More ...
Continue ReadingJuly 27, 2022
Sims v1.0 was discovered to allow path traversal when downloading attachments.Read More ...
Continue ReadingJuly 27, 2022
WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.Read More ...
Continue ReadingJuly 27, 2022
A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified ...
Continue ReadingJuly 27, 2022
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permissi ...
Continue ReadingJuly 27, 2022
A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configura ...
Continue ReadingJuly 27, 2022
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them ...
Continue ReadingJuly 27, 2022
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.Read More ...
Continue ReadingJuly 27, 2022
Back to Main