|
CVE-2020-4629
|
Low
|
2020-09-30
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
|
|
CVE-2020-26137
|
Medium
|
2020-09-30
|
No exploit published
|
No public exploit
|
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
|
|
CVE-2020-19676
|
Medium
|
2020-09-30
|
No exploit published
|
No public exploit
|
Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in. (detail:https://github.com/alibaba/nacos/issues/2284)
|
|
CVE-2020-13953
|
Medium
|
2020-09-30
|
No exploit published
|
No public exploit
|
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
|
|
CVE-2018-11765
|
High
|
2020-09-30
|
No exploit published
|
No public exploit
|
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
|
|
CVE-2020-15840
|
Medium
|
2020-09-24
|
No exploit published
|
No public exploit
|
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
|
|
CVE-2020-2285
|
Medium
|
2020-09-23
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
|
|
CVE-2020-2284
|
High
|
2020-09-23
|
Protected by RASP
|
No public exploit
|
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|
CVE-2020-2283
|
Medium
|
2020-09-23
|
No exploit published
|
No public exploit
|
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.
|
|
CVE-2020-2282
|
Medium
|
2020-09-23
|
No exploit published
|
No public exploit
|
Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to configure the plugin.
|
|
CVE-2020-2281
|
Medium
|
2020-09-23
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock, and reset resources.
|
|
CVE-2020-2280
|
High
|
2020-09-23
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execute arbitrary code.
|
|
CVE-2020-2279
|
Critical
|
2020-09-23
|
No exploit published
|
No public exploit
|
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide crafted return values or script binding content that can result in arbitrary code execution on the Jenkins controller JVM.
|
|
CVE-2020-10714
|
High
|
2020-09-23
|
No exploit published
|
No public exploit
|
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
|
|
CVE-2020-10687
|
Medium
|
2020-09-23
|
No exploit published
|
No public exploit
|
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
|
|
CVE-2020-15839
|
Medium
|
2020-09-22
|
No exploit published
|
No public exploit
|
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
|
|
CVE-2020-4643
|
High
|
2020-09-21
|
Protected by RASP
|
No public exploit
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
|
|
CVE-2020-4590
|
Medium
|
2020-09-21
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
|
|
CVE-2020-5421
|
Medium
|
2020-09-19
|
No exploit published
|
No public exploit
|
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
|
|
CVE-2020-25633
|
Medium
|
2020-09-18
|
No exploit published
|
No public exploit
|
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to data confidentiality.
|
|
CVE-2020-24750
|
High
|
2020-09-17
|
Protected by RASP
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
|
|
CVE-2020-14338
|
Medium
|
2020-09-17
|
No fix identified
|
No public exploit
|
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.
|
|
CVE-2020-7733
|
High
|
2020-09-16
|
No exploit published
|
No public exploit
|
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
|
|
CVE-2020-2278
|
Medium
|
2020-09-16
|
Protected by RASP
|
No public exploit
|
Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with Job/Configure permission to replace any other '.xml' file on the Jenkins controller with a job config.xml file's content.
|
|
CVE-2020-2277
|
Medium
|
2020-09-16
|
Protected by RASP
|
No public exploit
|
Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jenkins controller.
|
|
CVE-2020-2276
|
High
|
2020-09-16
|
Protected by RASP
|
No public exploit
|
Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure permission to execute an arbitrary system command on the Jenkins controller as the OS user that the Jenkins process is running as.
|
|
CVE-2020-2275
|
Medium
|
2020-09-16
|
Protected by RASP
|
No public exploit
|
Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.
|
|
CVE-2020-2274
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
|
|
CVE-2020-2273
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
|
|
CVE-2020-2272
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
|
|
CVE-2020-2271
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
|
|
CVE-2020-2270
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
|
|
CVE-2020-2269
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to configure views.
|
|
CVE-2020-2268
|
High
|
2020-09-16
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any arbitrary files on the Jenkins controller.
|
|
CVE-2020-2267
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to gain access to some metadata of any arbitrary files on the Jenkins controller.
|
|
CVE-2020-2266
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
|
|
CVE-2020-2265
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.
|
|
CVE-2020-2264
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
|
|
CVE-2020-2263
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
|
|
CVE-2020-2262
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.
|
|
CVE-2020-2261
|
High
|
2020-09-16
|
Protected by RASP
|
No public exploit
|
Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller
|
|
CVE-2020-2260
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.
|
|
CVE-2020-2259
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
|
|
CVE-2020-2258
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.
|
|
CVE-2020-2257
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
|
|
CVE-2020-2256
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
|
|
CVE-2020-2255
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Blue Ocean Plugin 1.23.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
|
|
CVE-2020-2254
|
Medium
|
2020-09-16
|
Protected by RASP
|
No public exploit
|
Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.
|
|
CVE-2020-2253
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured SMTP server.
|
|
CVE-2020-2252
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
|
|
CVE-2020-1748
|
High
|
2020-09-16
|
No exploit published
|
No public exploit
|
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
|
|
CVE-2020-1710
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
|
|
CVE-2020-1694
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
|
|
CVE-2020-13928
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability.
|
|
CVE-2020-10758
|
High
|
2020-09-16
|
No exploit published
|
No public exploit
|
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
|
|
CVE-2020-10748
|
Medium
|
2020-09-16
|
No exploit published
|
No public exploit
|
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
|
|
CVE-2020-10718
|
High
|
2020-09-16
|
No exploit published
|
No public exploit
|
A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which can bypass the security manager. The highest threat from this vulnerability is to confidentiality.
|
|
CVE-2020-11977
|
High
|
2020-09-15
|
Protected by RASP
|
No public exploit
|
In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution.
|
|
CVE-2020-24164
|
High
|
2020-09-11
|
Protected by RASP
|
No public exploit
|
A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.
|
|
CVE-2020-15171
|
Medium
|
2020-09-10
|
No exploit published
|
No public exploit
|
In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code execution. The only workaround is to give SCRIPT right only to trusted users.
|
|
CVE-2020-15170
|
High
|
2020-09-10
|
No exploit published
|
No public exploit
|
apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is designed to work in intranet and it doesn't have access control built-in. Malicious hackers may access apollo-adminservice apis directly to access/edit the application's configurations. To fix the potential issue without upgrading, simply follow the advice that do not expose apollo-adminservice to internet.
|
|
CVE-2020-13920
|
Medium
|
2020-09-10
|
No fix identified
|
No public exploit
|
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.
|
|
CVE-2020-14384
|
High
|
2020-09-09
|
No exploit published
|
No public exploit
|
A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.
|
|
CVE-2020-23811
|
High
|
2020-09-03
|
No exploit published
|
No public exploit
|
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
|
|
CVE-2020-24554
|
High
|
2020-09-01
|
No exploit published
|
No public exploit
|
The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.
|
|
CVE-2020-2251
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
|
|
CVE-2020-2250
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
|
|
CVE-2020-2249
|
Low
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
|
|
CVE-2020-2248
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability.
|
|
CVE-2020-2247
|
Medium
|
2020-09-01
|
Protected by RASP
|
No public exploit
|
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|
CVE-2020-2246
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Valgrind XML report contents.
|
|
CVE-2020-2245
|
High
|
2020-09-01
|
Protected by RASP
|
No public exploit
|
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|
CVE-2020-2244
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.
|
|
CVE-2020-2243
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
|
|
CVE-2020-2242
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.
|
|
CVE-2020-2241
|
High
|
2020-09-01
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified database server using attacker-specified credentials.
|
|
CVE-2020-2240
|
High
|
2020-09-01
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.
|
|
CVE-2020-2239
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
|
|
CVE-2020-2238
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
|
|
CVE-2020-13946
|
Medium
|
2020-09-01
|
No exploit published
|
No public exploit
|
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.
|