• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    公众号

CVE漏洞

RSS
  • CVE-2022-34801
    CVE-2022-34801
    Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:09 | 阅读:377 | 回复:0
  • CVE-2022-34802
    CVE-2022-34802
    Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by user ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:09 | 阅读:408 | 回复:0
  • CVE-2022-34803
    CVE-2022-34803
    Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extend ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:09 | 阅读:345 | 回复:0
  • CVE-2022-34804
    CVE-2022-34804
    Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:09 | 阅读:381 | 回复:0
  • CVE-2022-34805
    CVE-2022-34805
    Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins cont ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:09 | 阅读:373 | 回复:0
  • CVE-2022-34806
    CVE-2022-34806
    Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to th ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:09 | 阅读:395 | 回复:0
  • CVE-2022-34807
    CVE-2022-34807
    Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins c ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:09 | 阅读:349 | 回复:0
  • CVE-2022-34808
    CVE-2022-34808
    Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins co ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:09 | 阅读:370 | 回复:0
  • CVE-2022-34794
    CVE-2022-34794
    Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:08 | 阅读:383 | 回复:0
  • CVE-2022-34795
    CVE-2022-34795
    Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:08 | 阅读:366 | 回复:0
  • CVE-2022-34796
    CVE-2022-34796
    A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:08 | 阅读:360 | 回复:0
  • CVE-2022-34797
    CVE-2022-34797
    A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified crede ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:08 | 阅读:343 | 回复:0
  • CVE-2022-34798
    CVE-2022-34798
    Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specifie ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:08 | 阅读:332 | 回复:0
  • CVE-2022-34799
    CVE-2022-34799
    Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenki ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:08 | 阅读:412 | 回复:0
  • CVE-2022-34800
    CVE-2022-34800
    Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:08 | 阅读:338 | 回复:0
  • CVE-2022-34787
    CVE-2022-34787
    Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:07 | 阅读:413 | 回复:0
  • CVE-2022-34788
    CVE-2022-34788
    Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configur ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:07 | 阅读:364 | 回复:0
  • CVE-2022-34789
    CVE-2022-34789
    A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:07 | 阅读:338 | 回复:0
  • CVE-2022-34790
    CVE-2022-34790
    Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Ite ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:07 | 阅读:346 | 回复:0
  • CVE-2022-34791
    CVE-2022-34791
    Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:07 | 阅读:341 | 回复:0
  • CVE-2022-34792
    CVE-2022-34792
    A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:07 | 阅读:361 | 回复:0
  • CVE-2022-34793
    CVE-2022-34793
    Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:07 | 阅读:366 | 回复:0
  • CVE-2022-34779
    CVE-2022-34779
    A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:06 | 阅读:367 | 回复:0
  • CVE-2022-34780
    CVE-2022-34780
    A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified cr ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:06 | 阅读:338 | 回复:0
  • CVE-2022-34781
    CVE-2022-34781
    Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specifie ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:06 | 阅读:371 | 回复:0
  • CVE-2022-34782
    CVE-2022-34782
    An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:06 | 阅读:360 | 回复:0
  • CVE-2022-34783
    CVE-2022-34783
    Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:06 | 阅读:354 | 回复:0
  • CVE-2022-34784
    CVE-2022-34784
    Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update pe ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:06 | 阅读:362 | 回复:0
  • CVE-2022-34785
    CVE-2022-34785
    Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise i ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:06 | 阅读:356 | 回复:0
  • CVE-2022-34786
    CVE-2022-34786
    Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:06 | 阅读:404 | 回复:0
  • CVE-2022-22478
    CVE-2022-22478
    IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:05 | 阅读:339 | 回复:0
  • CVE-2022-22487
    CVE-2022-22487
    An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:05 | 阅读:415 | 回复:0
  • CVE-2022-22494
    CVE-2022-22494
    IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. Th ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:05 | 阅读:656 | 回复:0
  • CVE-2022-22496
    CVE-2022-22496
    While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be suscepti ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:05 | 阅读:334 | 回复:0
  • CVE-2022-31112
    CVE-2022-31112
    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:05 | 阅读:381 | 回复:0
  • CVE-2013-4144
    CVE-2013-4144
    There is an object injection vulnerability in swfupload plugin for wordpress.……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:05 | 阅读:358 | 回复:0
  • CVE-2022-34777
    CVE-2022-34777
    Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability explo ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:05 | 阅读:569 | 回复:0
  • CVE-2022-34778
    CVE-2022-34778
    Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messages provided in test results if certain job-level options are set, resulting in a ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:05 | 阅读:349 | 回复:0
  • CVE-2022-2056
    CVE-2022-2056
    Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:04 | 阅读:340 | 回复:0
  • CVE-2022-2057
    CVE-2022-2057
    Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f ...……
    作者:菜鸟教程小白 | 时间:2022-7-7 09:04 | 阅读:363 | 回复:0

关注我们

极客给你想要的成长

关注极客中国获取最新资讯

热门推荐
专题导读
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap