A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins c ...
Continue ReadingJuly 27, 2022
NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.Read More ...
Continue ReadingJuly 27, 2022
A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.Read More ...
Continue ReadingJuly 27, 2022
Jenkins Buckminster Plugin 1.1.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of ...
Continue ReadingJuly 27, 2022
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters, resulting in a stored cross-site scripting (XSS) vulnerability ex ...
Continue ReadingJuly 27, 2022
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.Read More ...
Continue ReadingJuly 27, 2022
Jenkins Repository Connector Plugin 2.2.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the exi ...
Continue ReadingJuly 27, 2022
A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of ...
Continue ReadingJuly 27, 2022
Back to Main