(RHSA-2023:3299) Important: jenkins and jenkins-2-plugins security update

Jenkins is a continuous integration server that monitors executions of repeated jobs, such as building a software project or jobs run by cron. Security Fix(es): * apache-commons-text: variable interpo ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2023-33941

Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update ...

Continue Reading
Spring Authorization Server is on Spring Initializr!

Today, I'm excited to announce that you have a new superpower: creating applications with [Spring Authorization Server]() on [Spring Initializr]()! That's right, it's time to begin your OAuth2 journey ...

Continue Reading
Jenkins WSO2 Oauth Plugin cross-site request forgery vulnerability

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not implement a state parameter in its OAuth flow, a unique and non-guessable value associated with each authentication request. This vulnerability allow ...

Continue Reading
Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the existing session on login. This allows attackers to use social engineering techniques to gain administrator access to Jenkins. As of p ...

Continue Reading
Jenkins WSO2 Oauth Plugin cross-site request forgery vulnerability

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not implement a state parameter in its OAuth flow, a unique and non-guessable value associated with each authentication request. This vulnerability allow ...

Continue Reading
Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the existing session on login. This allows attackers to use social engineering techniques to gain administrator access to Jenkins. As of p ...

Continue Reading
Jenkins Enterprise and Operations Center 2.346.x < 2.346.40.0.17 Multiple Vulnerabilities (CloudBees Security Advisory 2023-05-16)

The version of Jenkins Enterprise or Jenkins Operations Center running on the remote web server is 2.346.x prior to 2.346.40.0.17. It is, therefore, affected by multiple vulnerabilities including the ...

Continue Reading

Back to Main

Subscribe for the latest news: