Jenkins BigPanda Notifier Plugin stores BigPanda API key unencrypted

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to t ...

Continue Reading

CVSS3 - MEDIUM

Jenkins BigPanda Notifier Plugin stores BigPanda API key unencrypted

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to t ...

Continue Reading

CVSS3 - MEDIUM

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

### Impact An issue was discovered in Rancher versions up to and including 2.5.15 and 2.6.6 where sensitive fields, like passwords, API keys and Rancher's service account token (used to provision clus ...

Continue Reading

CVSS3 - MEDIUM

Metasploit Weekly Wrap-Up

## Have you built out that awesome media room? ![Metasploit Weekly Wrap-Up](https://blog.rapid7.com/content/images/2022/09/metasploit-fence-1.png) If your guilty pleasures include using a mobile devic ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

### Impact An issue was discovered in Rancher versions up to and including 2.5.15 and 2.6.6 where sensitive fields, like passwords, API keys and Rancher's service account token (used to provision clus ...

Continue Reading

CVSS3 - MEDIUM

Bitbucket Git Command Injection Exploit

Various versions of Bitbucket Server and Data Center are vulnerable to an unauthenticated command injection vulnerability in multiple API endpoints. The /rest/api/latest/projects/{projectKey}/repos/{r ...

Continue Reading

CVSS3 - HIGH

Jenkins BigPanda Notifier Plugin Missing Password Field Masking

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.Read More ...

Continue Reading

CVSS3 - MEDIUM

Jenkins Anchore Container Image Scanner Plugin vulnerable to cross site scripting

Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable ...

Continue Reading

CVSS3 - MEDIUM

Back to Main

Subscribe for the latest news: