|
CVE-2020-7009
|
High
|
2020-03-31
|
No exploit published
|
No public exploit
|
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
|
|
CVE-2020-11113
|
High
|
2020-03-31
|
Mitigation candidate
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
|
CVE-2020-11112
|
High
|
2020-03-31
|
Mitigation candidate
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
|
|
CVE-2020-11111
|
High
|
2020-03-31
|
Mitigation candidate
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
|
|
CVE-2020-7611
|
Critical
|
2020-03-30
|
No exploit published
|
No public exploit
|
All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.
|
|
CVE-2020-7599
|
Medium
|
2020-03-30
|
No exploit published
|
No public exploit
|
All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with the --info log level flag, the Gradle Logger logs an AWS pre-signed URL. If this build log is publicly visible (as it is in many popular public CI systems like TravisCI) this AWS pre-signed URL would allow a malicious actor to replace a recently uploaded plugin with their own.
|
|
CVE-2020-5289
|
Medium
|
2020-03-30
|
No exploit published
|
No public exploit
|
In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model. The adversary can construct filter expressions for an inaccessible field to filter a collection. The presence or absence of models in the returned collection can be used to reconstruct the value of the inaccessible field. Resolved in Elide 4.5.14 and greater.
|
|
CVE-2019-17561
|
High
|
2020-03-30
|
No exploit published
|
No public exploit
|
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
|
|
CVE-2019-17560
|
Critical
|
2020-03-30
|
No exploit published
|
No public exploit
|
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
|
|
CVE-2020-4276
|
High
|
2020-03-26
|
No fix identified
|
Proof of concept only
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
|
|
CVE-2020-10969
|
High
|
2020-03-26
|
Mitigation candidate
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
|
CVE-2020-10968
|
High
|
2020-03-26
|
Mitigation candidate
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
|
|
CVE-2020-2170
|
Medium
|
2020-03-25
|
No exploit published
|
No public exploit
|
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability.
|
|
CVE-2020-2169
|
Medium
|
2020-03-25
|
No exploit published
|
No public exploit
|
A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter displayed in an error message, resulting in a reflected XSS vulnerability.
|
|
CVE-2020-2165
|
High
|
2020-03-25
|
No exploit published
|
No public exploit
|
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
|
|
CVE-2020-2164
|
Medium
|
2020-03-25
|
No exploit published
|
No public exploit
|
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
|
|
CVE-2020-2163
|
Medium
|
2020-03-25
|
No exploit published
|
No public exploit
|
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
|
|
CVE-2020-2162
|
Medium
|
2020-03-25
|
No exploit published
|
No public exploit
|
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
|
|
CVE-2020-2161
|
Medium
|
2020-03-25
|
No exploit published
|
No public exploit
|
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
|
|
CVE-2020-2160
|
High
|
2020-03-25
|
No exploit published
|
No public exploit
|
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
|
|
CVE-2020-1957
|
Critical
|
2020-03-25
|
No exploit published
|
No public exploit
|
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
|
|
CVE-2020-1744
|
Medium
|
2020-03-24
|
No exploit published
|
No public exploit
|
A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.
|
|
CVE-2020-1951
|
Medium
|
2020-03-23
|
No exploit published
|
No public exploit
|
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
|
|
CVE-2020-1950
|
Medium
|
2020-03-23
|
No exploit published
|
No public exploit
|
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
|
|
CVE-2019-20527
|
Medium
|
2020-03-19
|
No exploit published
|
No public exploit
|
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
|
|
CVE-2019-20526
|
Medium
|
2020-03-19
|
No exploit published
|
No public exploit
|
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
|
|
CVE-2019-20525
|
Medium
|
2020-03-19
|
No exploit published
|
No public exploit
|
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
|
|
CVE-2019-19336
|
Medium
|
2020-03-19
|
No fix identified
|
No public exploit
|
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.
|
|
CVE-2019-12416
|
Medium
|
2020-03-19
|
No exploit published
|
No public exploit
|
we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.
|
|
CVE-2020-10673
|
High
|
2020-03-18
|
Mitigation candidate
|
Proof of concept only
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
|
CVE-2020-10672
|
High
|
2020-03-18
|
Mitigation candidate
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
|
CVE-2019-20528
|
Medium
|
2020-03-18
|
No exploit published
|
No public exploit
|
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
|
|
CVE-2019-19135
|
High
|
2020-03-16
|
No exploit published
|
No public exploit
|
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.
|
|
CVE-2019-10091
|
High
|
2020-03-16
|
No exploit published
|
No public exploit
|
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.
|
|
CVE-2020-10591
|
High
|
2020-03-15
|
No exploit published
|
No public exploit
|
An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and references to usernames via api/v1/apikey.
|
|
CVE-2020-1953
|
Critical
|
2020-03-13
|
No exploit published
|
No public exploit
|
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
|
|
CVE-2020-10544
|
Medium
|
2020-03-13
|
No exploit published
|
No public exploit
|
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
|
|
CVE-2020-6858
|
Medium
|
2020-03-12
|
No exploit published
|
No public exploit
|
Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header.
|
|
CVE-2019-11343
|
Critical
|
2020-03-12
|
No exploit published
|
No public exploit
|
Torpedo Query before 2.5.3 mishandles the LIKE operator in ConditionBuilder.java, LikeCondition.java, and NotLikeCondition.java.
|
|
CVE-2012-1094
|
High
|
2020-03-10
|
No exploit published
|
No public exploit
|
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.
|
|
CVE-2020-2157
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
|
|
CVE-2020-2156
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
|
|
CVE-2020-2155
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
|
|
CVE-2020-2154
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system.
|
|
CVE-2020-2153
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
|
|
CVE-2020-2152
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.
|
|
CVE-2020-2151
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
|
|
CVE-2020-2150
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
|
|
CVE-2020-2149
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
|
|
CVE-2020-2148
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.
|
|
CVE-2020-2147
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
|
|
CVE-2020-2146
|
High
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.
|
|
CVE-2020-2145
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.
|
|
CVE-2020-2143
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
|
|
CVE-2020-2142
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to trigger builds.
|
|
CVE-2020-2141
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.
|
|
CVE-2020-2140
|
Medium
|
2020-03-09
|
Mitigation candidate
|
Working exploit published
|
Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.
|
|
CVE-2020-2137
|
Medium
|
2020-03-09
|
No exploit published
|
No public exploit
|
Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
|
|
CVE-2020-2135
|
High
|
2020-03-09
|
No exploit published
|
No public exploit
|
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.
|
|
CVE-2020-2134
|
High
|
2020-03-09
|
No exploit published
|
No public exploit
|
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.
|
|
CVE-2019-14886
|
Medium
|
2020-03-05
|
No fix identified
|
No public exploit
|
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.
|
|
CVE-2020-5404
|
Medium
|
2020-03-03
|
No exploit published
|
No public exploit
|
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
|
|
CVE-2020-5403
|
High
|
2020-03-03
|
No exploit published
|
No public exploit
|
Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response.
|
|
CVE-2020-9548
|
Critical
|
2020-03-02
|
Mitigation candidate
|
Working exploit published
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
|
|
CVE-2020-9547
|
Critical
|
2020-03-02
|
Mitigation candidate
|
Working exploit published
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
|
|
CVE-2020-9546
|
Critical
|
2020-03-02
|
Mitigation candidate
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
|
|
CVE-2020-1731
|
Critical
|
2020-03-02
|
No exploit published
|
No public exploit
|
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
|
|
CVE-2019-14893
|
Critical
|
2020-03-02
|
Mitigation candidate
|
No public exploit
|
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.
|
|
CVE-2019-14892
|
Critical
|
2020-03-02
|
Mitigation candidate
|
No public exploit
|
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
|